Impact
The vulnerability arises from improper handling of the Password argument in the SET_USER_PWD Handler of the glc component, allowing an attacker to inject shell commands through crafted payloads. This leads to remote code execution on the GL.iNet GL‑MT3000 router. The weakness is rooted in CWE‑74 (Improper Neutralization of Input During Command Injection) and CWE‑77 (Improper Restriction of Commands or Command Interpreters).
Affected Systems
GL.iNet GL‑MT3000 devices running firmware versions up to 4.4.5 are affected. Firmware 4.8.1 and later contain the fix.
Risk and Exploitability
The CVSS base score for this issue is 6.9, reflecting a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The description confirms that the attack can be initiated remotely, suggesting that an attacker with network or web access to the device could exploit the flaw without additional privileges.
OpenCVE Enrichment