Description
A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-bin/glc of the component wg-server.so Native Plugin. Executing a manipulation of the argument private_key can lead to command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Published: 2026-08-03
Score: 9.3 Critical
EPSS: 2.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in GL‑iNet GL‑MT3000 firmware versions up to 4.4.5 within the wg‑server.so Native Plugin, specifically the wg-server.generate_publickey function in /cgi-bin/glc. By manipulating the private_key argument, an attacker can inject arbitrary commands, enabling remote code execution. The vulnerability is exploitable over the network and has already been publicly disclosed.

Affected Systems

GL‑iNet GL‑MT3000 routers running firmware 4.4.5 or earlier are affected. The flaw targets the firmware’s wg‑server.so Native Plugin and the /cgi-bin/glc component.

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity, and the EPSS score is 2%, indicating a low but non‑zero probability of exploitation. The confirmed remote attack vector and the publicly disclosed nature suggest a high likelihood of exploitation. The vulnerability is not listed in CISA KEV, but the ability to execute commands remotely makes it a severe risk. Attackers can reach the vulnerable endpoint via standard HTTP requests to the device’s web interface, sending a crafted private_key value that the plugin does not properly validate, thus achieving command injection.

Generated by OpenCVE AI on August 4, 2026 at 20:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade GL‑iNet firmware to a version newer than 4.4.5 or apply the vendor’s official patch if available.
  • Restrict network access to the wg‑server.so service by limiting the interface, using firewall rules, or disabling remote administration.
  • Apply input validation or sanitization on the private_key parameter in the /cgi-bin/glc handler, ensuring no shell metacharacters are passed through.

Generated by OpenCVE AI on August 4, 2026 at 20:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Gl-inet gl-mt3000
Vendors & Products Gl-inet gl-mt3000

Mon, 03 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-bin/glc of the component wg-server.so Native Plugin. Executing a manipulation of the argument private_key can lead to command injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Title GL-iNet GL-MT3000 wg-server.so Native Plugin glc wg-server.generate_publickey command injection
First Time appeared Gl-inet
Gl-inet gl-mt3000 Firmware
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:o:gl-inet:gl-mt3000_firmware:*:*:*:*:*:*:*:*
Vendors & Products Gl-inet
Gl-inet gl-mt3000 Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Gl-inet Gl-mt3000 Gl-mt3000 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-03T20:17:48.811Z

Reserved: 2026-08-03T07:33:29.637Z

Link: CVE-2026-18615

cve-icon Vulnrichment

Updated: 2026-08-03T20:17:44.572Z

cve-icon NVD

Status : Deferred

Published: 2026-08-03T19:16:45.383

Modified: 2026-08-12T21:00:37.147

Link: CVE-2026-18615

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T21:00:11Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')