Description
A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Published: 2026-08-03
Score: 9.3 Critical
EPSS: 3.6% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A command injection vulnerability exists in the s2s.enable_echo_server endpoint of the /cgi-bin/glc interface in GL‑iNet GL‑MT3000 firmware up to version 4.4.5. By supplying a crafted port argument, an attacker can execute arbitrary shell commands with the privileges of the web service, enabling full device compromise, configuration changes, data exfiltration, or reuse of the device as part of a larger attack.

Affected Systems

GL‑iNet GL‑MT3000 routers with firmware up to version 4.4.5 are affected. The vulnerability exists in the s2s.so native plugin accessed via the /cgi-bin/glc interface.

Risk and Exploitability

The CVSS score of 9.3 classifies the flaw as critical. The EPSS of 4% indicates a measurable likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Remote attackers can exploit it via the device’s HTTP interface, typically over a local network or the Internet, making it an attractive target for adversaries.

Generated by OpenCVE AI on September 24, 2026 at 20:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware update released by GL‑iNet that patches the command injection flaw.
  • If a patch is not yet available, restrict or block external access to /cgi-bin/glc using firewall, VPN, or deny the endpoint from the network perimeter.
  • Disable the s2s.enable_echo_server feature in the router’s configuration if it is not required for the environment.
  • Validate and sanitize the port input on the server side to prevent command injection, addressing the underlying CWE-74 and CWE-77 weaknesses.

Generated by OpenCVE AI on September 24, 2026 at 20:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Gl-inet gl-mt3000
Vendors & Products Gl-inet gl-mt3000

Mon, 03 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Title GL-iNet GL-MT3000 s2s.so Native Plugin glc s2s.enable_echo_server command injection
First Time appeared Gl-inet
Gl-inet gl-mt3000 Firmware
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:o:gl-inet:gl-mt3000_firmware:*:*:*:*:*:*:*:*
Vendors & Products Gl-inet
Gl-inet gl-mt3000 Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Gl-inet Gl-mt3000 Gl-mt3000 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-03T18:53:45.564Z

Reserved: 2026-08-03T07:33:25.401Z

Link: CVE-2026-18614

cve-icon Vulnrichment

Updated: 2026-08-03T18:53:42.506Z

cve-icon NVD

Status : Deferred

Published: 2026-08-03T19:16:45.200

Modified: 2026-08-12T21:00:37.147

Link: CVE-2026-18614

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T21:00:18Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')