What is CVE-2026-18685?
A command injection vulnerability has been found in the `set_upgrade` function of the `modem.so` component in `/cgi-bin/glc` on GL.iNet GL-MT3000 devices running firmware up to version 4.4.5. This allows remote attackers to execute arbitrary commands on the affected device. Users are advised to update to the latest firmware immediately.
Azərbaycanca: GL.iNet GL-MT3000 cihazının 4.4.5 versiyasına qədər olan proqram təminatında, `/cgi-bin/glc` faylındakı `modem.so` komponentinin `set_upgrade` funksiyasında command injection zəifliyi aşkarlanıb. Bu boşluq uzaqdan hücum edən şəxsə cihazda ixtiyari əmrlər icra etməyə imkan verir. İstifadəçilərə dərhal ən son proqram təminatına yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: GL.iNet
FAQ2
Which firmware versions of the GL.iNet GL-MT3000 are affected by the command injection vulnerability?
The vulnerability affects firmware versions up to 4.4.5.
What can an attacker achieve by exploiting this vulnerability?
A remote attacker can execute arbitrary commands on the device.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.