Description
A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Published: 2026-08-03
Score: 9.3 Critical
EPSS: 2.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the set_upgrade function of the /cgi-bin/glc component (modem.so) allows an attacker to inject arbitrary commands. The weakness stems from improper validation of input passed to the operating‑system shell, corresponding to CWE‑74 and CWE‑77, and enables remote code execution by malicious actors.

Affected Systems

The vulnerability affects GL.iNet GL‑MT3000 devices running firmware versions up to and including 4.4.5. The issue resides in the modem.so module exposed via the glc CGI endpoint.

Risk and Exploitability

With a CVSS score of 9.3, the weakness is highly severe. An attacker can remotely craft input to the set_upgrade call and trigger any shell command, giving full control over the device. The EPSS score is 2%, indicating a realistic likelihood of abuse. The vulnerability is not currently listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 4, 2026 at 20:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the GL.iNet firmware to a version newer than 4.4.5 that contains the fix for the set_upgrade command injection.
  • If an updated image is not yet available, block external access to the /cgi-bin/glc endpoint or place the device behind a firewall that denies unsolicited remote traffic.
  • Ensure that default credentials are changed and that device access is limited to trusted network segments.

Generated by OpenCVE AI on August 4, 2026 at 20:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Gl-inet gl-mt3000
Vendors & Products Gl-inet gl-mt3000

Mon, 03 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Title GL.iNet GL-MT3000 modem.so glc set_upgrade command injection
First Time appeared Gl-inet
Gl-inet gl-mt3000 Firmware
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:o:gl-inet:gl-mt3000_firmware:*:*:*:*:*:*:*:*
Vendors & Products Gl-inet
Gl-inet gl-mt3000 Firmware
References
Metrics cvssV2_0

{'score': 10, 'vector': 'AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Gl-inet Gl-mt3000 Gl-mt3000 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-04T14:19:21.884Z

Reserved: 2026-08-03T15:50:05.082Z

Link: CVE-2026-18685

cve-icon Vulnrichment

Updated: 2026-08-04T14:19:17.914Z

cve-icon NVD

Status : Deferred

Published: 2026-08-04T00:16:40.350

Modified: 2026-08-12T20:59:00.027

Link: CVE-2026-18685

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T20:45:03Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')