Description
A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function realpath of the file /rpc of the component Minidlna Service. This manipulation of the argument kube. set causes command injection. The attack is possible to be carried out remotely. Upgrading to version 4.7 is sufficient to fix this issue. It is recommended to upgrade the affected component. The vendor confirms: "Starting from version 4.7, SDK has added global protection to intercept malicious injection".
Published: 2026-06-07
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in the realpath function within the Minidlna Service rpc endpoint on GL.iNet GL-MT3000 firmware up to version 4.4.5. An attacker can supply a crafted kube.set argument that causes the realpath routine to execute arbitrary commands. This flaw permits remote execution of commands with the privileges of the running Minidlna service, leading to unauthorized code execution. The weakness is identified by CWE-74 (Command Injection) and CWE-77 (Path Traversal).

Affected Systems

The affected devices are GL.iNet GL-MT3000 routers running firmware versions 4.4.5 or earlier. The Minidlna Service component is part of the device firmware, and the fault exists in the rpc interface handling the kube.set parameter. Any router with firmware that has not been updated to 4.7 or later is susceptible.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that large‑scale exploitation has not been observed. The flaw can be exercised remotely without user interaction, provided the attacker can reach the rpc endpoint. Because the vulnerability allows arbitrary command execution, it poses a high impact if exploited.

Generated by OpenCVE AI on June 7, 2026 at 03:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the GL.iNet GL-MT3000 firmware to version 4.7 or later, which includes the proper command injection protection.
  • Verify that the Minidlna Service is no longer responsive to untrusted kube.set parameters (if possible).
  • If an upgrade is not immediately possible, disable the Minidlna Service or restrict access to the rpc interface to trusted local networks.

Generated by OpenCVE AI on June 7, 2026 at 03:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 07 Jun 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Gl-inet gl-mt3000
Vendors & Products Gl-inet gl-mt3000

Sun, 07 Jun 2026 02:45:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function realpath of the file /rpc of the component Minidlna Service. This manipulation of the argument kube. set causes command injection. The attack is possible to be carried out remotely. Upgrading to version 4.7 is sufficient to fix this issue. It is recommended to upgrade the affected component. The vendor confirms: "Starting from version 4.7, SDK has added global protection to intercept malicious injection".
Title GL.iNet GL-MT3000 Minidlna Service rpc realpath command injection
First Time appeared Gl-inet
Gl-inet gl-mt3000 Firmware
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:o:gl-inet:gl-mt3000_firmware:*:*:*:*:*:*:*:*
Vendors & Products Gl-inet
Gl-inet gl-mt3000 Firmware
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Gl-inet Gl-mt3000 Gl-mt3000 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-06-07T02:00:13.687Z

Reserved: 2026-06-06T10:33:12.835Z

Link: CVE-2026-11448

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-07T03:16:26.233

Modified: 2026-06-07T03:16:26.233

Link: CVE-2026-11448

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-07T04:00:11Z

Weaknesses