GL.iNet GL-MT3000是中国广联智通(GL.iNet)公司的一款支持Wi-Fi 6和VPN功能的便携式旅行路由器。 GL.iNet GL-MT3000 4.4.5及之前版本存在命令注入漏洞,该漏洞源于SET_USER_PWD Handler组件文件/cgi-bin/glc中函数FUN_0042e200对参数Password的错误操作,可能导致命令注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-11451 | 7.3 HIGH | GL.iNet GL-MT3000 FTP Protocol glc snprintf command injection |
| CVE-2026-11450 | 7.3 HIGH | GL.iNet GL-MT3000 Path Normalization dlopen command injection |
| CVE-2026-11449 | 6.3 MEDIUM | GL.iNet GL-MT3000 LuCI JSON-RPC rpc rpc_sys command injection |
| CVE-2026-11447 | 6.3 MEDIUM | GL.iNet GL-MT3000 MTK Backend iwinfo.so iwinfo_backend command injection |
| CVE-2026-11448 | 4.7 MEDIUM | GL.iNet GL-MT3000 Minidlna Service rpc realpath command injection |
No comments yet