PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18585 GL.iNet CVE debrief

A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000, and MT2500 up to 20260707. The affected element is the function nas-web.get_file_list of the component APPS-NAS Module. Performing a manipulation results in heap-based buffer overflow. The attack may be initiated remotely. This issue affects various GL.iNet devices, potentially allowing attackers to manipulate the function and cause a buffer overflow. Users should verify affected product deployments and review official advisories for further details.

Vendor
GL.iNet
Product
GL.iNet devices (APPS‑NAS Module)
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-03
Original CVE updated
2026-08-03
Advisory published
2026-08-03
Advisory updated
2026-08-03

Who should care

GL.iNet device users, network administrators, and security teams should be aware of this vulnerability and take necessary actions to protect their systems. They should inventory and verify affected GL.iNet devices, apply vendor patches or updates when available, and monitor network traffic to the APPS-NAS Module. Additionally, they should implement compensating controls for heap-based buffer overflow and review and track exceptions for exposed systems.

Technical summary

The vulnerability is caused by a heap-based buffer overflow in the nas-web.get_file_list function of the APPS-NAS Module in GL.iNet devices. This can be exploited remotely, allowing attackers to manipulate the function and cause a buffer overflow. The affected products include GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000, and MT2500 up to 20260707. Defenders should focus on verifying affected product deployments, applying vendor patches or updates when available, and implementing compensating controls for heap-based buffer overflow.

Defensive priority

Medium priority due to remote attack possibility and vendor confirmation.

Recommended defensive actions

  • Inventory and verify affected GL.iNet devices
  • Apply vendor patches or updates when available
  • Monitor network traffic to APPS-NAS Module
  • Implement compensating controls for heap-based buffer overflow
  • Review and track exceptions for exposed systems
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The CVE record and NVD entry provide initial details. Further analysis is required to fully understand the vulnerability's impact and affected scope. The vulnerability affects GL.iNet devices, specifically the APPS-NAS Module's nas-web.get_file_list function, leading to a heap-based buffer overflow. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations. They should also review compensating controls for exposed systems and check relevant monitoring, detection, and logs for exposed assets.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-03T06:16:37.710Z and has not been modified since then.