PT-2026-47175 · Gl.Inet · Gl-Mt3000

·

CVE-2026-11452

·

Published

2026-05-12

·

Updated

2026-06-07

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GL.iNet GL-MT3000 versions prior to 4.8.1
Description Command injection is possible via a remote attack in the SET USER PWD Handler component. The issue exists within the FUN 0042e200() function of the '/cgi-bin/glc' file, where improper manipulation of the Password argument allows for the execution of arbitrary commands.
Recommendations Upgrade to version 4.8.1.

Fix

Command Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07966
CVE-2026-11452

Affected Products

Gl-Mt3000