Impact
A flaw in the set_upgrade function of the /cgi-bin/glc component (modem.so) allows an attacker to inject arbitrary commands. The weakness stems from improper validation of input passed to the operating‑system shell, corresponding to CWE‑74 and CWE‑77, and enables remote code execution by malicious actors.
Affected Systems
The vulnerability affects GL.iNet GL‑MT3000 devices running firmware versions up to and including 4.4.5. The issue resides in the modem.so module exposed via the glc CGI endpoint.
Risk and Exploitability
With a CVSS score of 9.3, the weakness is highly severe. An attacker can remotely craft input to the set_upgrade call and trigger any shell command, giving full control over the device. The EPSS score is 2%, indicating a realistic likelihood of abuse. The vulnerability is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment