What is CVE-2026-18601?
CVE-2026-18601 is a command injection vulnerability affecting GL.iNet GL-MT3000 devices running firmware up to version 4.4.5. The flaw exists in the ovpn-client.check_config function within the /cgi-bin/glc file of the ovpn-client.so Native Plugin, triggered by manipulating the 'filename' argument, and can be exploited remotely. Users are advised to update their device firmware to the latest version.
Azərbaycanca: CVE-2026-18601 GL.iNet GL-MT3000 cihazlarında 4.4.5 versiyasına qədər mövcud olan əmr yeridilməsi (command injection) zəifliyidir. Bu, ovpn-client.so Native Plugin-in /cgi-bin/glc faylındakı ovpn-client.check_config funksiyasında 'filename' arqumentinin manipulyasiyası nəticəsində baş verir və uzaqdan istismar oluna bilər. İstifadəçilərə cihaz proqram təminatını ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: GL.iNet
FAQ2
How can I protect my GL.iNet GL-MT3000 device from CVE-2026-18601?
You should update your device firmware to the latest version, as this command injection vulnerability exists up to version 4.4.5.
Which component in GL-MT3000 is affected by CVE-2026-18601?
The vulnerability occurs in the ovpn-client.check_config function within the /cgi-bin/glc file of the ovpn-client.so Native Plugin, via manipulation of the 'filename' argument.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.