Critical Command Injection Flaw in GL-iNet
A severe RCE vulnerability in GL-MT3000 routers allows unauthenticated remote attackers to execute arbitrary system commands.
A critical vulnerability, tracked as CVE-2026-18616, has been identified in the GL-iNet GL-MT3000 router. The flaw resides in the wg-server.so native plugin, specifically within the server.set_peer function, and allows for remote command injection through the public_key argument. Because the exploit is publicly available, users are at immediate risk of unauthorized system access.
What's at Risk
The vulnerability affects GL-iNet GL-MT3000 devices running firmware versions up to 4.4.5. The impact is categorized with a CVSS 3.1 score of 9.8, indicating a critical severity level. This flaw is particularly dangerous for any organization or individual using these devices in internet-facing configurations, as the vulnerability does not require authentication to exploit.
When a device is exposed to the public internet, it becomes a target for automated scanning and exploitation tools. If an attacker successfully leverages this command injection, they gain the ability to execute arbitrary code on the underlying operating system, potentially leading to a complete compromise of the router and any network traffic passing through it.
How the Flaw Works
Command injection occurs when an application fails to properly sanitize user-supplied data before passing it to a system shell or an execution environment. In general, this type of weakness allows an attacker to append malicious commands to legitimate input fields. The system then inadvertently executes these commands with the privileges of the application process.
By manipulating specific arguments—in this case, the public_key—an attacker can escape the intended function constraints and trigger the execution of unintended commands. This class of vulnerability is highly prized by attackers because it often provides a direct path to full system control without the need for complex bypasses or specialized credentials.
How to Protect Your Systems
- Verify your current firmware version and update to the latest available release from GL-iNet immediately.
- Restrict management access to the router to trusted internal IP addresses only.
- Disable remote administration features if they are not strictly required for your operational needs.
- Implement network segmentation to isolate critical devices from potentially compromised networking hardware.
- Monitor system logs for unusual activity or unexpected execution patterns that may indicate an attempted exploit.
Given the critical severity of CVE-2026-18616 and the availability of public exploit code, prompt remediation is the only effective way to mitigate this risk. Delaying updates leaves the device open to remote exploitation, potentially resulting in full system compromise and loss of network integrity.
Sources
- NVD Original source
Continue Reading
Apple Counters U.K. Data Access Demand
Apple has filed a formal challenge against a U.K. government directive seeking access to encrypted iCloud user data.
Critical Krayin CRM Flaw Enables Takeover
A missing authentication vulnerability in Krayin CRM version 2.2.4 allows remote attackers to hijack the administrator account and gain full system access.
Critical RCE Flaw Found in OpenEMR 8.2.0
A critical remote code execution vulnerability in OpenEMR allows authenticated administrators to run arbitrary OS commands via the document category tree.