Description
A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Published: 2026-08-03
Score: 9.3 Critical
EPSS: 2.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A command injection flaw exists in the GL-iNet GL-MT3000 firmware, specifically within the s2s.enable_echo_server endpoint of the s2s.so native plugin accessed via /cgi-bin/glc. By manipulating the port argument, an attacker can execute arbitrary shell commands with the privileges of the web service. This leads to full compromise of the device, allowing the attacker to alter configurations, exfiltrate data, or use the device as a foothold in a larger attack.

Affected Systems

All GL-MT3000 devices running firmware version 4.4.5 or earlier, as identified by the vendor GL-iNet. The affected component is the s2s.so native plugin, which is present in the supplied firmware builds.

Risk and Exploitability

The flaw carries a CVSS score of 9.3, indicating critical severity. The EPSS score is 2%, indicating a non-negligible likelihood of real‑world attacks. The vulnerability is not listed in the CISA KEV catalog, yet remote exploitation is possible through the device’s web interface, making it a valuable target for attackers. The primary attack vector is remote, local network or Internet access to the device’s HTTP interface.

Generated by OpenCVE AI on August 4, 2026 at 20:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and apply the latest GL-MT3000 firmware update that removes the command injection flaw.
  • If no update is available, restrict network access to /cgi-bin/glc by placing the device behind a firewall or VPN, and block the original port that is used for s2s.enable_echo_server.
  • Consider disabling or removing the s2s.enable_echo_server functionality in device configuration, if the feature is optional and not required for your environment.

Generated by OpenCVE AI on August 4, 2026 at 20:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Gl-inet gl-mt3000
Vendors & Products Gl-inet gl-mt3000

Mon, 03 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Title GL-iNet GL-MT3000 s2s.so Native Plugin glc s2s.enable_echo_server command injection
First Time appeared Gl-inet
Gl-inet gl-mt3000 Firmware
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:o:gl-inet:gl-mt3000_firmware:*:*:*:*:*:*:*:*
Vendors & Products Gl-inet
Gl-inet gl-mt3000 Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Gl-inet Gl-mt3000 Gl-mt3000 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-03T18:53:45.564Z

Reserved: 2026-08-03T07:33:25.401Z

Link: CVE-2026-18614

cve-icon Vulnrichment

Updated: 2026-08-03T18:53:42.506Z

cve-icon NVD

Status : Deferred

Published: 2026-08-03T19:16:45.200

Modified: 2026-08-12T21:00:37.147

Link: CVE-2026-18614

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T21:00:11Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')