What is CVE-2026-18602?
A command injection vulnerability was identified in GL.iNet GL-MT3000 up to version 4.4.5, specifically in the 'ovpn-client.so' native plugin. The flaw exists in the 'ovpn-client.get_recommend_config' function within '/cgi-bin/glc', where manipulation of the 'Hostname' argument allows remote command execution. Users should immediately update to the latest firmware and restrict open network access to the device.
Azərbaycanca: GL.iNet GL-MT3000 cihazının 4.4.5-ə qədər versiyalarında 'ovpn-client.so' komponentində command injection zəifliyi aşkarlanıb. '/cgi-bin/glc' faylındakı 'ovpn-client.get_recommend_config' funksiyasında Hostname arqumentinin manipulyasiyası vasitəsilə uzaqdan əmr yeridilməsi mümkündür. Cihaz sahibləri dərhal proqram təminatını son versiyaya yeniləməli və açıq şəbəkə girişlərini məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: GL.iNet
FAQ1
What vulnerability has been found in my GL.iNet GL-MT3000 device and how can I protect it?
A command injection vulnerability (CVE-2026-18602) was identified in the 'ovpn-client.so' component in versions up to 4.4.5. You should immediately update to the latest firmware and restrict open network access to the device.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.