What is CVE-2026-18686?
A command injection vulnerability was detected in GL.iNet GL-MT3000 routers up to version 4.4.5, specifically in the `nas-web.add_user` function within the `/cgi-bin/glc` file's nas-web RPC Wrapper. This allows remote attackers to execute arbitrary commands on the system. Users are advised to update their device firmware to the latest version.
Azərbaycanca: GL.iNet GL-MT3000 routerinin 4.4.5-ə qədər versiyalarında, `/cgi-bin/glc` faylındakı `nas-web.add_user` funksiyasında Command Injection zəifliyi aşkar edilib. Bu boşluq uzaqdan hücum edən şəxsə sistemdə əmr icra etməyə imkan verir. İstifadəçilərə cihaz proqram təminatını ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: GL.iNet
FAQ2
How can I protect against the CVE-2026-18686 vulnerability found in GL.iNet GL-MT3000 routers?
Users are advised to update their device firmware to the latest version.
In which function of the GL.iNet GL-MT3000 does the CVE-2026-18686 vulnerability exist?
The vulnerability was detected in the `nas-web.add_user` function within the `/cgi-bin/glc` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.