Impact
A misconfigured plugins.set_config function in the GL-iNet GL-MT3000 firmware allows a remote attacker to inject arbitrary data into the native plugin. The injection can be exploited to execute malicious code or commands on the device, compromising confidentiality, integrity, and availability. The flaw is exposed in the /cgi-bin/glc endpoint and is triggered by specially crafted requests.
Affected Systems
The vulnerability affects GL-iNet GL-MT3000 routers running firmware version 4.4.5 or earlier. This includes all models deployed in consumer, small‑business, and industrial settings that have not yet upgraded beyond the cited firmware.
Risk and Exploitability
The CVSS score of 9.3 reflects a high severity and the absence of an available EPSS score suggests limited current exploitation data; however, the vulnerability has been publicly disclosed and can be accessed remotely. The flaw is not listed in the CISA KEV catalog, but its injection vector does not require local access, making it suitable for widespread exploitation once a patch is released.
OpenCVE Enrichment