Impact
The vulnerability is a command injection flaw located in the server.set_peer function of the wg‑server.so native plugin (cgi-bin/glc) on GL‑iNet GL‑MT3000 routers. Attackers can manipulate the public_key argument to inject arbitrary operating‑system commands, giving them full control of the device. The flaw is a classic input validation failure (CWE‑74/CWE‑77) and could compromise confidentiality, integrity, and availability of the affected router.
Affected Systems
The issue affects GL‑iNet GL‑MT3000 routers running firmware versions up to and including 4.4.5. No other vendors or product lines are currently known to be impacted.
Risk and Exploitability
The CVSS base score of 9.3 indicates extreme severity. Remote exploitation is possible, and an exploit is publicly available, with an EPSS score of 2%. The vulnerability is not yet listed in CISA KEV, but the combination of remote code execution and known public exploits makes it highly likely to be targeted soon. Attackers could reach the device over the network and trigger the command injection by crafted requests to /cgi-bin/glc with a malicious public_key payload.
OpenCVE Enrichment