GL.iNet vulnerabilities
13 CVEs tracked
GL.iNet appears in our reporting due to critical command injection vulnerabilities affecting GL-MT3000 and AX1800 router models. The primary theme is remote code execution via various RPC endpoints and Native Plugins. Vulnerabilities include CVE-2026-18600, CVE-2026-18601, CVE-2026-18602, CVE-2026-18598, CVE-2026-18599, CVE-2026-18685, CVE-2026-18686 (GL-MT3000, up to 4.4.5) and CVE-2026-18787 (AX1800, up to 4.8.3). Defenders should prioritize patching these devices and restrict access to management interfaces, especially those exposed to the internet.
Azərbaycanca: GL.iNet hesabatlarımızda GL-MT3000 və AX1800 router modelləri üçün ciddi command injection zəiflikləri ilə bağlı görünür. Müşahidə olunan əsas mövzu müxtəlif RPC endpoint-ləri və Native Plugin-lər vasitəsilə uzaqdan kod icrasına imkan verən zəifliklərdir. CVE-2026-18600, CVE-2026-18601, CVE-2026-18602, CVE-2026-18598, CVE-2026-18599, CVE-2026-18685, CVE-2026-18686 (GL-MT3000, 4.4.5-ə qədər) və CVE-2026-18787 (AX1800, 4.8.3-ə qədər) zəiflikləri identifikasiya edilib. Müdafiəçilər bu cihazları mümkün qədər tez yamalamağa, xüsusilə internetə baxan idarəetmə interfeyslərini məhdudlaşdırmağa diqqət etməlidir.
This vendor's CVEs13
This hub is built from skopnix's own reporting on GL.iNet: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.