Impact
A command injection flaw exists in the GL-iNet GL-MT3000 firmware, specifically within the s2s.enable_echo_server endpoint of the s2s.so native plugin accessed via /cgi-bin/glc. By manipulating the port argument, an attacker can execute arbitrary shell commands with the privileges of the web service. This leads to full compromise of the device, allowing the attacker to alter configurations, exfiltrate data, or use the device as a foothold in a larger attack.
Affected Systems
All GL-MT3000 devices running firmware version 4.4.5 or earlier, as identified by the vendor GL-iNet. The affected component is the s2s.so native plugin, which is present in the supplied firmware builds.
Risk and Exploitability
The flaw carries a CVSS score of 9.3, indicating critical severity. The EPSS score is 2%, indicating a non-negligible likelihood of real‑world attacks. The vulnerability is not listed in the CISA KEV catalog, yet remote exploitation is possible through the device’s web interface, making it a valuable target for attackers. The primary attack vector is remote, local network or Internet access to the device’s HTTP interface.
OpenCVE Enrichment