Impact
A command‑injection flaw exists in the remove_profile function of the modem.so component on GL.iNet GL‑MT3000 devices running firmware 4.4.5 or earlier. A remote attacker can supply crafted input to the /cgi‑bin/glc CGI endpoint, causing the device to execute arbitrary shell commands. This allows full compromise of the device, including data exfiltration, persistence, or pivoting to other network resources. The flaw is assigned a CVSS score of 9.3, indicating critical severity.
Affected Systems
The affected product is GL.iNet GL‑MT3000 routers whose firmware versions are 4.4.5 or earlier, as identified by the component modem.so.
Risk and Exploitability
The CVSS score of 9.3 reflects high impact and potential for remote exploitation. The EPSS score is 2%, and the vulnerability is not yet listed in the CISA KEV catalog. However, the exploit code has been published openly, and the presence of a web‑based attacker interface suggests that any device exposed to untrusted traffic is at risk. An attacker can trigger the vulnerability from outside the local network if the device exposes the necessary endpoints.
OpenCVE Enrichment