Description
A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Published: 2026-08-03
Score: 9.3 Critical
EPSS: 2.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A command‑injection flaw exists in the remove_profile function of the modem.so component on GL.iNet GL‑MT3000 devices running firmware 4.4.5 or earlier. A remote attacker can supply crafted input to the /cgi‑bin/glc CGI endpoint, causing the device to execute arbitrary shell commands. This allows full compromise of the device, including data exfiltration, persistence, or pivoting to other network resources. The flaw is assigned a CVSS score of 9.3, indicating critical severity.

Affected Systems

The affected product is GL.iNet GL‑MT3000 routers whose firmware versions are 4.4.5 or earlier, as identified by the component modem.so.

Risk and Exploitability

The CVSS score of 9.3 reflects high impact and potential for remote exploitation. The EPSS score is 2%, and the vulnerability is not yet listed in the CISA KEV catalog. However, the exploit code has been published openly, and the presence of a web‑based attacker interface suggests that any device exposed to untrusted traffic is at risk. An attacker can trigger the vulnerability from outside the local network if the device exposes the necessary endpoints.

Generated by OpenCVE AI on August 4, 2026 at 20:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to a version where the remove_profile command is patched or disabled.
  • Restrict external access to the device by placing it behind a firewall and exposing only necessary services over a secure, private network.
  • Monitor network traffic and device logs for attempts to hit the /cgi_bin/glc endpoint with suspicious parameters.

Generated by OpenCVE AI on August 4, 2026 at 20:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Gl-inet gl-mt3000
Vendors & Products Gl-inet gl-mt3000

Mon, 03 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Title GL.iNet GL-MT3000 modem.so glc remove_profile command injection
First Time appeared Gl-inet
Gl-inet gl-mt3000 Firmware
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:o:gl-inet:gl-mt3000_firmware:*:*:*:*:*:*:*:*
Vendors & Products Gl-inet
Gl-inet gl-mt3000 Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Gl-inet Gl-mt3000 Gl-mt3000 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-04T15:41:00.345Z

Reserved: 2026-08-03T15:49:55.918Z

Link: CVE-2026-18684

cve-icon Vulnrichment

Updated: 2026-08-04T15:40:34.425Z

cve-icon NVD

Status : Deferred

Published: 2026-08-03T23:16:45.750

Modified: 2026-08-12T20:59:00.027

Link: CVE-2026-18684

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T20:45:03Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')