GL.iNet XE3000是中国GL.iNet公司的一款便携式路由器。 GL.iNet XE3000 20260707及之前版本存在安全漏洞,该漏洞源于eSIM LPA API组件的/sdk/v1文件中的未知功能存在授权不当,可能导致本地网络中的攻击者发起未授权操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GL.iNet | E5800 | 20260707 |
cpe:2.3:a:gl.inet:e5800:*:*:*:*:*:*:*:*
|
|
| GL.iNet | E750 | 20260707 |
cpe:2.3:a:gl.inet:e750:*:*:*:*:*:*:*:*
|
|
| GL.iNet | X2000 | 20260707 |
cpe:2.3:a:gl.inet:x2000:*:*:*:*:*:*:*:*
|
|
| GL.iNet | X3000 | 20260707 |
cpe:2.3:a:gl.inet:x3000:*:*:*:*:*:*:*:*
|
|
| GL.iNet | XE3000 | 20260707 |
cpe:2.3:a:gl.inet:xe3000:*:*:*:*:*:*:*:*
|
|
| GL.iNet | XE300 | 20260707 |
cpe:2.3:a:gl.inet:xe300:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18601 | 9.8 CRITICAL | GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.check_config command inject |
| CVE-2026-18602 | 9.8 CRITICAL | GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.get_recommend_config comman |
| CVE-2026-18684 | 9.8 CRITICAL | GL.iNet GL-MT3000 modem.so glc remove_profile command injection |
| CVE-2026-18685 | 9.8 CRITICAL | GL.iNet GL-MT3000 modem.so glc set_upgrade command injection |
| CVE-2026-18598 | 8.8 HIGH | GL.iNet GL-MT3000 Logread Lua RPC plugin logread logread.get_system_log command injection |
| CVE-2026-18600 | 8.8 HIGH | GL.iNet GL-MT3000 Network Lua RPC Plugin network network.switch_status command injection |
| CVE-2026-18599 | 8.0 HIGH | GL.iNet GL-MT3000 Logread Lua RPC Plugin logread logread.set_config command injection |
| CVE-2026-18585 | 4.3 MEDIUM | GL.iNet MT2500 APPS-NAS nas-web.get_file_list heap-based overflow |
No comments yet