Description
A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. The affected element is the function nas-web.get_file_list of the component APPS-NAS Module. Performing a manipulation results in heap-based buffer overflow. The attack may be initiated remotely. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Published: 2026-08-03
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap‑based buffer overflow exists in the nas‑web.get_file_list function of the APPS‑NAS module. The vulnerability can be triggered by sending a specially crafted request, causing the application to corrupt memory and crash. The result is a denial of service that can be executed from a remote location, indicating that the flaw is exploitable without disclosure of additional details. The weakness is classified as CWE-119 and CWE-122, indicating untrusted input handling and improper bounds checking.

Affected Systems

GL.iNet devices BE3600, BE6500, BE9300, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X3000, and XE3000, with affected firmware versions up to the release dated 2026‑07‑07. The vulnerability is present in all listed models’ APPS‑NAS module before this date.

Risk and Exploitability

The CVSS v3 score is 5.3, reflecting moderate severity. EPSS data is unavailable and the flaw is not listed in the CISA KEV catalog, suggesting limited known exploitation. The description states that the attack may be initiated remotely by submitting a manipulated request to nas‑web.get_file_list; the CVE payload does not specify any particular authentication or privilege requirements, so it is unclear whether the exploit requires valid credentials or can be performed by unauthenticated users. Once triggered, the buffer overflow causes the service to crash, leading to unavailability of the NAS functionality until the device is rebooted or patched.

Generated by OpenCVE AI on August 4, 2026 at 10:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑released update that addresses the buffer overflow in the APPS‑NAS module as soon as it becomes available.
  • Limit exposure of the NAS web interface by configuring firewalls or VPNs to allow only trusted networks or IP addresses to reach the nas‑web service.
  • If the APPS‑NAS module is not required, disable or remove the module to eliminate the exploitation vector.
  • Monitor logs for anomalous or repeated requests to the nas‑web.get_file_list endpoint, and investigate any unexpected activity.

Generated by OpenCVE AI on August 4, 2026 at 10:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Gl-inet
Gl-inet be3600
Gl-inet be6500
Gl-inet be9300
Gl-inet e5800
Gl-inet mt2500
Gl-inet mt3000
Gl-inet mt3600be
Gl-inet mt5000
Gl-inet mt6000
Gl-inet x3000
Gl-inet xe3000
Vendors & Products Gl-inet
Gl-inet be3600
Gl-inet be6500
Gl-inet be9300
Gl-inet e5800
Gl-inet mt2500
Gl-inet mt3000
Gl-inet mt3600be
Gl-inet mt5000
Gl-inet mt6000
Gl-inet x3000
Gl-inet xe3000

Mon, 03 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. The affected element is the function nas-web.get_file_list of the component APPS-NAS Module. Performing a manipulation results in heap-based buffer overflow. The attack may be initiated remotely. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Title GL.iNet MT2500 APPS-NAS nas-web.get_file_list heap-based overflow
First Time appeared Gl.inet
Gl.inet be3600
Gl.inet be6500
Gl.inet be9300
Gl.inet e5800
Gl.inet mt2500
Gl.inet mt3000
Gl.inet mt3600be
Gl.inet mt5000
Gl.inet mt6000
Gl.inet x3000
Gl.inet xe3000
Weaknesses CWE-119
CWE-122
CPEs cpe:2.3:a:gl.inet:be3600:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:be6500:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:be9300:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:e5800:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:mt2500:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:mt3000:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:mt3600be:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:mt5000:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:mt6000:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:x3000:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:xe3000:*:*:*:*:*:*:*:*
Vendors & Products Gl.inet
Gl.inet be3600
Gl.inet be6500
Gl.inet be9300
Gl.inet e5800
Gl.inet mt2500
Gl.inet mt3000
Gl.inet mt3600be
Gl.inet mt5000
Gl.inet mt6000
Gl.inet x3000
Gl.inet xe3000
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:N/A:P/E:ND/RL:ND/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-03T13:21:10.843Z

Reserved: 2026-08-02T19:24:01.254Z

Link: CVE-2026-18585

cve-icon Vulnrichment

Updated: 2026-08-03T13:20:58.229Z

cve-icon NVD

Status : Deferred

Published: 2026-08-03T06:16:37.710

Modified: 2026-08-12T21:00:37.147

Link: CVE-2026-18585

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T10:45:05Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-122

    Heap-based Buffer Overflow