Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.9
CVE-2026-18613: GL-iNet GL-MT3000 Plugin Configuration Data Injection
CVE-2026-18613 · published 1 month ago
Summary
An attacker can remotely inject malicious data into the GL-iNet GL-MT3000's plugin configuration. This allows them to potentially take control of the device. To protect your device, update to the latest version of the software, which has already been released by the vendor.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| gl-inet | gl-mt3000 | 4.4.0 |
Original advisory text
A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the component plugins.so Native Plugin. Such manipula...
A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the component plugins.so Native Plugin. Such manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
References
- https://vuldb.com/vuln/385533 vdb-entry technical-description
- https://vuldb.com/vuln/385533/cti signature permissions-required
- https://vuldb.com/cve/CVE-2026-18613 third-party-advisory
- https://vuldb.com/submit/851557 third-party-advisory
- https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/plugins_set_... exploit
Severity
8.9
High
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-74Injection
CWE-707Improper Neutralization
Timeline
Published3 Aug 2026
Updated27 Sep 2026
First seen3 Aug 2026
Track software like this
Free during beta