Impact
The vulnerability lies in the realpath function within the Minidlna Service rpc endpoint on GL.iNet GL-MT3000 firmware up to version 4.4.5. An attacker can supply a crafted kube.set argument that causes the realpath routine to execute arbitrary commands. This flaw permits remote execution of commands with the privileges of the running Minidlna service, leading to unauthorized code execution. The weakness is identified by CWE-74 (Command Injection) and CWE-77 (Path Traversal).
Affected Systems
The affected devices are GL.iNet GL-MT3000 routers running firmware versions 4.4.5 or earlier. The Minidlna Service component is part of the device firmware, and the fault exists in the rpc interface handling the kube.set parameter. Any router with firmware that has not been updated to 4.7 or later is susceptible.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that large‑scale exploitation has not been observed. The flaw can be exercised remotely without user interaction, provided the attacker can reach the rpc endpoint. Because the vulnerability allows arbitrary command execution, it poses a high impact if exploited.
OpenCVE Enrichment