What is CVE-2026-18600?
A critical command injection vulnerability in GL.iNet GL-MT3000 routers up to version 4.4.5 allows remote code execution through the `network.switch_info`/`network.switch_status` Lua RPC functions due to insufficient validation of the `switch` argument. Immediate firmware update is strongly recommended for affected devices.
Azərbaycanca: GL.iNet GL-MT3000 marşrutlaşdırıcılarında 4.4.5 versiyasına qədər kritik əmr inyeksiyası boşluğu aşkarlanıb. Bu zəiflik `network.switch_info`/`network.switch_status` Lua RPC funksiyası vasitəsilə `switch` arqumentinin yoxlanılmaması səbəbindən uzaqdan kod icrasına imkan verir. Təsirlənmiş cihazlarda dərhal proqram təminatını yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: GL.iNet
FAQ2
How dangerous is the CVE-2026-18600 vulnerability found in GL.iNet GL-MT3000 routers?
This is a critical command injection vulnerability that allows remote code execution (RCE). An attacker can execute arbitrary commands on the device via the `switch` argument in the `network.switch_info` or `network.switch_status` Lua RPC functions.
What should I do to protect against CVE-2026-18600?
You should immediately update your affected GL.iNet GL-MT3000 device to the latest firmware version. This vulnerability exists up to version 4.4.5.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.