PT-2026-49110 · Gl.Inet · Gl-Mt3000

Strforexc

·

Published

2026-06-14

·

Updated

2026-06-14

·

CVE-2026-12187

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GL.iNet GL-MT3000 versions prior to 4.7
Description An issue in the Online Firmware Upgrade Handler component allows for remote command injection via the /usr/bin/one click upgrade file. Command injection is a flaw that allows an attacker to execute arbitrary operating system commands on the target machine.
Recommendations Update to version 4.7.

Exploit

Fix

Command Injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-12187

Affected Products

Gl-Mt3000