Description
A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the component plugins.so Native Plugin. Such manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Published: 2026-08-03
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A misconfigured plugins.set_config function in the GL-iNet GL-MT3000 firmware allows a remote attacker to inject arbitrary data into the native plugin. The injection can be exploited to execute malicious code or commands on the device, compromising confidentiality, integrity, and availability. The flaw is exposed in the /cgi-bin/glc endpoint and is triggered by specially crafted requests.

Affected Systems

The vulnerability affects GL-iNet GL-MT3000 routers running firmware version 4.4.5 or earlier. This includes all models deployed in consumer, small‑business, and industrial settings that have not yet upgraded beyond the cited firmware.

Risk and Exploitability

The CVSS score of 9.3 reflects a high severity and the absence of an available EPSS score suggests limited current exploitation data; however, the vulnerability has been publicly disclosed and can be accessed remotely. The flaw is not listed in the CISA KEV catalog, but its injection vector does not require local access, making it suitable for widespread exploitation once a patch is released.

Generated by OpenCVE AI on August 4, 2026 at 10:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade GL-iNet GL-MT3000 firmware to the latest release that contains the plugin injection fix (currently version >4.4.5).
  • If an immediate firmware upgrade is not possible, disable or remove the plugins.so component or block the /cgi-bin/glc endpoint using local firewall rules to prevent remote access.
  • Apply network segmentation or VLAN isolation to limit exposure of the router and monitor traffic for unusual plugin.set_config activity.

Generated by OpenCVE AI on August 4, 2026 at 10:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Gl-inet gl-mt3000
Vendors & Products Gl-inet gl-mt3000

Mon, 03 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the component plugins.so Native Plugin. Such manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Title GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection
First Time appeared Gl-inet
Gl-inet gl-mt3000 Firmware
Weaknesses CWE-707
CWE-74
CPEs cpe:2.3:o:gl-inet:gl-mt3000_firmware:*:*:*:*:*:*:*:*
Vendors & Products Gl-inet
Gl-inet gl-mt3000 Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Gl-inet Gl-mt3000 Gl-mt3000 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-03T21:19:17.133Z

Reserved: 2026-08-03T07:33:21.492Z

Link: CVE-2026-18613

cve-icon Vulnrichment

Updated: 2026-08-03T21:16:44.063Z

cve-icon NVD

Status : Deferred

Published: 2026-08-03T18:16:38.617

Modified: 2026-08-12T21:00:37.147

Link: CVE-2026-18613

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T10:15:04Z

Weaknesses
  • CWE-707

    Improper Neutralization

  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')