What is CVE-2026-18599?
CVE-2026-18599 is a command injection vulnerability in the `logread.set_config` function of GL.iNet GL-MT3000 routers (up to version 4.4.5). The flaw allows remote code execution via manipulation of the `record_size` argument. Users should immediately update their device firmware to the latest version.
Azərbaycanca: CVE-2026-18599, GL.iNet GL-MT3000 cihazlarının 4.4.5 versiyasına qədər olan `logread.set_config` funksiyasında aşkar edilmiş command injection zəifliyidir. Bu qüsur `record_size` arqumenti vasitəsilə uzaqdan kod icrasına imkan verir. İstifadəçilərə dərhal cihaz proqram təminatını ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: GL.iNet
FAQ2
Which function in my GL-MT3000 router is susceptible to command injection?
The CVE-2026-18599 vulnerability specifically affects the `logread.set_config` function. An attacker can achieve remote code execution by manipulating the `record_size` argument.
What should I do to protect against CVE-2026-18599?
You must update your device firmware to the latest version, as the vulnerability is confirmed for GL-MT3000 routers running up to version 4.4.5.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.