What is CVE-2026-18598?
A command injection vulnerability was found in the `logread.get_system_log` function of the Logread Lua RPC plugin in GL.iNet GL-MT3000 routers up to version 4.4.5. Remote attackers could exploit this to execute arbitrary commands; updating to the latest firmware is strongly recommended.
Azərbaycanca: GL.iNet GL-MT3000 routerin 4.4.5-ə qədər versiyalarında Logread Lua RPC plugin daxilində `logread.get_system_log` funksiyasında command injection zəifliyi aşkarlanıb. Bu, hücumçuya uzaqdan əmr yeritməyə imkan yaradır; cihazı dərhal ən son proqram təminatına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: GL.iNet
FAQ2
Which version of the GL.iNet GL-MT3000 router is vulnerable to CVE-2026-18598 command injection?
The vulnerability was found in versions up to 4.4.5. It is recommended to update your device to the latest firmware.
What can an attacker do by exploiting CVE-2026-18598?
An attacker can perform remote command execution through the `logread.get_system_log` function in the Logread Lua RPC plugin.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.