GL.iNet GL-MT3000是中国广联智通(GL.iNet)公司的一款支持Wi-Fi 6和VPN功能的便携式旅行路由器。 GL.iNet GL-MT3000 4.4.5及之前版本存在命令注入漏洞,该漏洞源于Minidlna Service组件文件/rpc中函数realpath对参数kube.set的错误操作,可能导致命令注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11452 | 7.3 HIGH | GL.iNet GL-MT3000 SET_USER_PWD glc FUN_0042e200 command injection |
| CVE-2026-11451 | 7.3 HIGH | GL.iNet GL-MT3000 FTP Protocol glc snprintf command injection |
| CVE-2026-11450 | 7.3 HIGH | GL.iNet GL-MT3000 Path Normalization dlopen command injection |
| CVE-2026-11449 | 6.3 MEDIUM | GL.iNet GL-MT3000 LuCI JSON-RPC rpc rpc_sys command injection |
| CVE-2026-11447 | 6.3 MEDIUM | GL.iNet GL-MT3000 MTK Backend iwinfo.so iwinfo_backend command injection |
No comments yet