Impact
The GL.iNet GL‑MT3000 firmware contains a command injection flaw in the nas‑web.add_user RPC function located in /cgi-bin/glc. This vulnerability allows an unauthenticated attacker to craft input that is executed as system commands on the device, giving full control over the device’s operating system and compromising confidentiality, integrity, and availability of the device.
Affected Systems
All GL.iNet GL‑MT3000 routers with firmware versions up to and including 4.4.5 are vulnerable. Devices beyond 4.4.5 are presumed to be unaffected until a vendor fix is released.
Risk and Exploitability
The CVSS score of 9.3 marks this flaw as critical. The EPSS score of 0.02607 indicates a low to moderate probability that exploitation attempts will occur, yet evidence of public exploit code exists. The flaw is not listed in the CISA KEV catalog, but it can be accessed remotely, typically over the Internet or a compromised local network, by sending a specially crafted request to the nas‑web.add_user endpoint.
OpenCVE Enrichment