<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>GL-INet - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/gl-inet/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 03 Aug 2026 20:05:56 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/gl-inet/feed.xml" rel="self" type="application/rss+xml"/><item><title>Remote Command Injection in GL-iNet GL-MT3000 Firmware</title><link>https://feed.craftedsignal.io/briefs/2026-08-gl-inet-rce/</link><pubDate>Mon, 03 Aug 2026 20:05:56 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-gl-inet-rce/</guid><description>A critical command injection vulnerability in the GL-iNet GL-MT3000 router firmware (up to 4.4.5) allows remote, unauthenticated attackers to execute arbitrary commands via the /cgi-bin/glc binary.</description><content:encoded><![CDATA[<p>A critical security vulnerability (CVE-2026-18612) has been identified in the GL-iNet GL-MT3000 router firmware, affecting all versions up to and including 4.4.5. The vulnerability resides within the 'plugins.so' native plugin, specifically impacting the 'plugins.remove_package' and 'plugins.install_package' functions invoked via the '/cgi-bin/glc' CGI binary. An unauthenticated, remote attacker can leverage this flaw to perform command injection, resulting in full remote code execution on the device.</p>
<p>Public exploit code has been released, significantly lowering the barrier for exploitation. Given the prevalence of this hardware in edge and small-office network environments, organizations utilizing these devices should prioritize patching or restricting access to the management interface. The vendor has acknowledged the flaw, and users are advised to update to the latest available firmware version that addresses this issue.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability carries a CVSS 3.1 base score of 9.8 (Critical), indicating high risk for confidentiality, integrity, and availability. Successful exploitation grants an attacker administrative control over the router, enabling further network compromise, traffic interception, or the deployment of persistent implants within the affected network.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update GL-iNet GL-MT3000 firmware to the latest version immediately to remediate CVE-2026-18612.</li>
<li>Restrict access to the router's web management interface to trusted internal IP ranges or VPNs.</li>
<li>Deploy web application firewall or IDS/IPS signatures capable of detecting anomalous POST requests targeting '/cgi-bin/glc' with suspicious shell metacharacters (e.g., ;, |, &amp;&amp;).</li>
<li>Deploy the provided Sigma rule to monitor for suspicious attempts to access the vulnerable CGI binary.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>cve-2026-18612</category><category>remote-code-execution</category><category>command-injection</category><category>router</category><category>cve-2026-18614</category><category>network-device</category><category>rce</category><category>network-security</category><category>cve-2026-18615</category></item></channel></rss>