Description
A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the component wg-server.so Native Plugin. The manipulation of the argument public_key leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Published: 2026-08-03
Score: 9.3 Critical
EPSS: 2.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a command injection flaw located in the server.set_peer function of the wg‑server.so native plugin (cgi-bin/glc) on GL‑iNet GL‑MT3000 routers. Attackers can manipulate the public_key argument to inject arbitrary operating‑system commands, giving them full control of the device. The flaw is a classic input validation failure (CWE‑74/CWE‑77) and could compromise confidentiality, integrity, and availability of the affected router.

Affected Systems

The issue affects GL‑iNet GL‑MT3000 routers running firmware versions up to and including 4.4.5. No other vendors or product lines are currently known to be impacted.

Risk and Exploitability

The CVSS base score of 9.3 indicates extreme severity. Remote exploitation is possible, and an exploit is publicly available, with an EPSS score of 2%. The vulnerability is not yet listed in CISA KEV, but the combination of remote code execution and known public exploits makes it highly likely to be targeted soon. Attackers could reach the device over the network and trigger the command injection by crafted requests to /cgi-bin/glc with a malicious public_key payload.

Generated by OpenCVE AI on August 4, 2026 at 20:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and flash the latest firmware release that fixes the server.set_peer command injection.
  • If an update is unavailable or delayed, block the wg-server.so service or restrict access to the /cgi-bin/glc endpoint using firewall or ACL rules.
  • Enable logging and monitor for anomalous requests containing the public_key parameter or unexpected shell commands; investigate any suspicious activity immediately.

Generated by OpenCVE AI on August 4, 2026 at 20:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Gl-inet gl-mt3000
Vendors & Products Gl-inet gl-mt3000

Mon, 03 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the component wg-server.so Native Plugin. The manipulation of the argument public_key leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Title GL-iNet GL-MT3000 wg-server.so Native Plugin glc server.set_peer command injection
First Time appeared Gl-inet
Gl-inet gl-mt3000 Firmware
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:o:gl-inet:gl-mt3000_firmware:*:*:*:*:*:*:*:*
Vendors & Products Gl-inet
Gl-inet gl-mt3000 Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Gl-inet Gl-mt3000 Gl-mt3000 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-04T17:13:28.400Z

Reserved: 2026-08-03T07:33:34.035Z

Link: CVE-2026-18616

cve-icon Vulnrichment

Updated: 2026-08-04T17:13:24.814Z

cve-icon NVD

Status : Deferred

Published: 2026-08-03T19:16:45.557

Modified: 2026-08-12T20:59:00.027

Link: CVE-2026-18616

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T21:00:11Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')