PatchSiren

GL-iNet CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH GL.iNet CVE published 2026-06-14

CVE-2026-12187

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Affected by this vulnerability is an unknown functionality of the file /usr/bin/one_click_upgrade of the component Online Firmware Upgrade Handler. Such manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 4.7 addresses this iss [truncated]

HIGH GL.iNet CVE published 2026-06-14

CVE-2026-12186

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function replace_country in the library /usr/lib/oui-httpd/rpc/tor of the component Tor Proxy Service Configuration Handler. This manipulation causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 4.7 is able to add [truncated]

LOW GL.iNet CVE published 2026-06-08

CVE-2026-11505

A vulnerability has been identified in multiple GL.iNet devices, including A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000, and XE3000 running firmware version 4.8.x. This vulnerability affects an unknown function within the glnassys component, potentially allowing remote attackers to utilize a hard-coded cryptographic key. The attack is considered difficult to execute, requiring a high level of com [truncated]

MEDIUM GL.iNet CVE published 2026-06-07

CVE-2026-11452

A command injection vulnerability has been discovered in GL.iNet GL-MT3000 up to 4.4.5. The vulnerability affects the SET_USER_PWD Handler in the /cgi-bin/glc file, specifically in the FUN_0042e200 function. The manipulation of the Password argument leads to command injection, allowing remote attackers to execute arbitrary commands. The vulnerability has a CVSS score of 6.9 and is classified as MEDIUM sev [truncated]

MEDIUM GL.iNet CVE published 2026-06-07

CVE-2026-11451

A vulnerability was discovered in GL.iNet GL-MT3000 version 4.4.5. The issue lies in the snprintf function of the /cgi-bin/glc file within the FTP Protocol Handler component. An attacker can exploit this by manipulating the media_dir argument, leading to command injection. This attack can be launched remotely. The vulnerability has a CVSS score of 6.9 and is classified as MEDIUM severity. The issue is res [truncated]

MEDIUM GL.iNet CVE published 2026-06-07

CVE-2026-11450

A command injection vulnerability was detected in GL.iNet GL-MT3000 version 4.4.5. This vulnerability affects the function dlopen in the library /usr/lib/oui-httpd/rpc/ of the component Path Normalization Handler. An attacker can manipulate the argument dev_name to inject commands, allowing for a remote attack. The vulnerability has a CVSS score of 6.9 and is classified as MEDIUM severity. Upgrading to ve [truncated]

MEDIUM GL.iNet CVE published 2026-06-07

CVE-2026-11448

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function realpath of the file /rpc of the component Minidlna Service. This manipulation of the argument kube. set causes command injection. The attack is possible to be carried out remotely. Upgrading to version 4.7 is sufficient to fix this issue. It is recommended to upgrade the affected component. The vendor co [truncated]

LOW GL.iNet CVE published 2026-06-06

CVE-2026-11406

A vulnerability was determined in GL.iNet MT3000 up to 4.4.5. This vulnerability affects unknown code of the file ovpnclient.sh of the component OpenVPN Client Import Workflow. This manipulation causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 4.9.0_beta3-1012-0513-1778656146 is able to resolve this i [truncated]

MEDIUM GL-iNet CVE published 2026-03-17

CVE-2026-32291

The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 has a critical vulnerability that allows unauthenticated root access via the UART serial console. This attack requires physical access to the device and connection to the UART pins. The vulnerability was reported on March 10, 2026, and publicly disclosed on March 17, 2026. The CVSS score for this vulnerability is 6.8, indicating a medium severity. The vu [truncated]

MEDIUM GL-iNet CVE published 2026-03-17

CVE-2026-32290

The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 has a vulnerability that allows an attacker-in-the-middle or a compromised update server to modify the firmware and the corresponding MD5 hash to pass verification. This issue arises from insufficient verification of uploaded firmware files. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 4.7, indicating a medium severity l [truncated]