Impact
A bug in the GL.iNet GL‑MT3000 router’s ovpn‑client.so Native Plugin allows an attacker to manipulate the Hostname argument of the ovpn‑client.get_recommend_config command, resulting in arbitrary shell command execution and full system compromise.
Affected Systems
The vulnerability affects GL.iNet GL‑MT3000 routers running firmware versions up to 4.4.5. It is localized to the ovpn‑client.so component accessed via the /cgi‑bin/glc interface and does not affect other products or firmware releases beyond the specified version range.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity, while the EPSS score is 2%, indicating a low but non‑zero likelihood of exploitation. The vulnerability is listed in the CVE database and the exploit has been publicly disclosed, meaning a remote attacker could trigger it by sending a specially crafted HTTP request to /cgi‑bin/glc with a malicious Hostname value. It is not yet listed in the CISA KEV catalog, but given its high impact, it remains a high‑risk issue. The weakness stems from command injection (CWE‑74 and CWE‑77) and can be exploited over the network without authentication if the web interface is exposed.
OpenCVE Enrichment