No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 03 Aug 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gl-inet gl-mt3000
|
|
| Vendors & Products |
Gl-inet gl-mt3000
|
Mon, 03 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC Plugin. This manipulation of the argument record_size causes command injection. The exploit has been published and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. | |
| Title | GL.iNet GL-MT3000 Logread Lua RPC Plugin logread logread.set_config command injection | |
| First Time appeared |
Gl-inet
Gl-inet gl-mt3000 Firmware |
|
| Weaknesses | CWE-74 CWE-77 |
|
| CPEs | cpe:2.3:o:gl-inet:gl-mt3000_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gl-inet
Gl-inet gl-mt3000 Firmware |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-03T12:00:09.629Z
Reserved: 2026-08-03T06:55:15.299Z
Link: CVE-2026-18599
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-03T13:30:04Z