Impact
The vulnerability resides in GL‑iNet GL‑MT3000 firmware versions up to 4.4.5 within the wg‑server.so Native Plugin, specifically the wg-server.generate_publickey function in /cgi-bin/glc. By manipulating the private_key argument, an attacker can inject arbitrary commands, enabling remote code execution. The vulnerability is exploitable over the network and has already been publicly disclosed.
Affected Systems
GL‑iNet GL‑MT3000 routers running firmware 4.4.5 or earlier are affected. The flaw targets the firmware’s wg‑server.so Native Plugin and the /cgi-bin/glc component.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, and the EPSS score is 2%, indicating a low but non‑zero probability of exploitation. The confirmed remote attack vector and the publicly disclosed nature suggest a high likelihood of exploitation. The vulnerability is not listed in CISA KEV, but the ability to execute commands remotely makes it a severe risk. Attackers can reach the vulnerable endpoint via standard HTTP requests to the device’s web interface, sending a crafted private_key value that the plugin does not properly validate, thus achieving command injection.
OpenCVE Enrichment