CVE-2026-18616: A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the component wg-server.so Native
A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the component wg-server.so Native Plugin. The manipulation of the argument public_key leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-18616
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-18616 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for GL-iNet GL-MT3000
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalCVE-2026-18615: A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the f…nvd · 2026-08-03
- criticalCVE-2026-18614: A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enabl…nvd · 2026-08-03
- criticalCVE-2026-18613: A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the functi…nvd · 2026-08-03
- criticalCVE-2026-18612: A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the functio…nvd · 2026-08-03
More from NVD Recent CVEs
- highCVE-2026-59913: Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missin…2026-08-03
- highCVE-2026-59912: Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Impro…2026-08-03
- unknownCVE-2026-38447: osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The …2026-08-03
- unknownCVE-2026-38446: A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sa…2026-08-03
- unknownCVE-2026-38444: osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header …2026-08-03