Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.9
CVE-2026-18684: GL.iNet GL-MT3000 Modem Remote Command Execution
CVE-2026-18684 · published 1 month ago
Summary
A security weakness in the GL.iNet GL-MT3000 modem allows attackers to execute unauthorized commands remotely. This could be used to gain control of the modem or disrupt its operation. Users should update their modems to the latest version to fix this issue.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| gl.inet | gl-mt3000 | 4.4.0 |
Original advisory text
A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. This manipulation causes command ...
A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
References
- https://vuldb.com/vuln/385610 vdb-entry technical-description
- https://vuldb.com/vuln/385610/cti signature permissions-required
- https://vuldb.com/cve/CVE-2026-18684 third-party-advisory
- https://vuldb.com/submit/851581 third-party-advisory
- https://github.com/StrTzz123/iot_vul/tree/main/GL-iNet/MT3000/4.4.5/modem_remove... exploit
Severity
8.9
High
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS 4%
Type
CWE-77Command Injection
CWE-74Injection
Timeline
Published3 Aug 2026
Updated25 Sep 2026
First seen3 Aug 2026
Track software like this
Free during beta