GL.iNet GL-MT3000是中国广联智通(GL.iNet)公司的一款支持Wi-Fi 6和VPN功能的便携式旅行路由器。 GL.iNet GL-MT3000 4.4.5版本存在命令注入漏洞,该漏洞源于Path Normalization Handler组件库/usr/lib/oui-httpd/rpc/中函数dlopen对参数dev_name的错误操作,可能导致命令注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-11452 | 7.3 HIGH | GL.iNet GL-MT3000 SET_USER_PWD glc FUN_0042e200 command injection |
| CVE-2026-11451 | 7.3 HIGH | GL.iNet GL-MT3000 FTP Protocol glc snprintf command injection |
| CVE-2026-11449 | 6.3 MEDIUM | GL.iNet GL-MT3000 LuCI JSON-RPC rpc rpc_sys command injection |
| CVE-2026-11447 | 6.3 MEDIUM | GL.iNet GL-MT3000 MTK Backend iwinfo.so iwinfo_backend command injection |
| CVE-2026-11448 | 4.7 MEDIUM | GL.iNet GL-MT3000 Minidlna Service rpc realpath command injection |
No comments yet