Impact
A vulnerability in the Logread Lua RPC Plugin of GL.iNet GL-MT3000 firmware up to version 4.4.5 allows an attacker to manipulate the record_size argument passed to the logread.set_config function. This misuse permits arbitrary command execution on the device. Based on the description, it is inferred that successful exploitation could grant the attacker full control over the router, enabling data exfiltration, device takeover, or denial of service. The weakness is a classic command injection flaw (CWE-74) combined with insufficient input validation (CWE-77).
Affected Systems
GL.iNet GL-MT3000 routers running firmware versions 4.4.5 and earlier are affected. The vulnerability resides in /usr/lib/oui-httpd/rpc/logread. No other vendors or products are mentioned in the CNA data.
Risk and Exploitability
The CVSS score of 8.6 classifies this issue as High, and the exploitation is already documented and remotely exploitable. The EPSS score of 1.4% indicates a low but non‑zero exploitation probability, and the vulnerability is not yet listed in the CISA KEV catalog. Based on the description, it is inferred that attackers can reach the vulnerable RPC endpoint over the router’s HTTP interface, and that the level of authentication required depends on the device’s configuration, with the RPC interface typically exposed to the local network.
OpenCVE Enrichment