Impact
A command injection vulnerability exists in the s2s.enable_echo_server endpoint of the /cgi-bin/glc interface in GL‑iNet GL‑MT3000 firmware up to version 4.4.5. By supplying a crafted port argument, an attacker can execute arbitrary shell commands with the privileges of the web service, enabling full device compromise, configuration changes, data exfiltration, or reuse of the device as part of a larger attack.
Affected Systems
GL‑iNet GL‑MT3000 routers with firmware up to version 4.4.5 are affected. The vulnerability exists in the s2s.so native plugin accessed via the /cgi-bin/glc interface.
Risk and Exploitability
The CVSS score of 9.3 classifies the flaw as critical. The EPSS of 4% indicates a measurable likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Remote attackers can exploit it via the device’s HTTP interface, typically over a local network or the Internet, making it an attractive target for adversaries.
OpenCVE Enrichment