Impact
A flaw in GL-iNet GL-MT3000 firmware up to version 4.4.5 allows an attacker to inject arbitrary shell commands through the plugins.remove_package and plugins.install_package functions in the glc component. The vulnerability is a classic command injection flaw, classified as CWE-74 and CWE-77, enabling remote execution of system commands on the device. It can lead to full compromise of the device, allowing attackers to gain persistent access, exfiltrate data, or use the router as a foothold for further network attacks.
Affected Systems
GL-iNet GL-MT3000 routers running firmware versions up to 4.4.5 are affected, specifically those using the native plugins.so module accessed via the /cgi-bin/glc interface.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. The EPSS score is 2%, indicating a low but non-zero exploitation probability, but the vulnerability has an exposed exploit that has been published, implying that attacks are realistic. The issue remains outside the CISA KEV catalog. Because the attack vector is remote—any party can reach the vulnerable CGI endpoint—an attacker does not need local access to exploit it.
OpenCVE Enrichment