PT-2026-47174 · Gl.Inet · Gl-Mt3000

·

CVE-2026-11451

·

Published

2026-05-11

·

Updated

2026-06-07

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GL.iNet GL-MT3000 versions prior to 4.8.1
Description A flaw in the FTP Protocol Handler component allows remote command injection. The issue exists within the snprintf() function of the /cgi-bin/glc file. By manipulating the media dir argument via the /NAS API SET PROTO CONFIG interface, an attacker can execute arbitrary commands on the system.
Recommendations Update to version 4.8.1. As a temporary mitigation, restrict access to the /NAS API SET PROTO CONFIG interface to minimize the risk of exploitation.

Exploit

Fix

Command Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07967
CVE-2026-11451

Affected Products

Gl-Mt3000