๐ต๏ธ RESEARCH & DEEP DIVES
- Critical Command Injection Flaw Found in GL.iNet GL-MT3000 up to Firmware 4.4.5
CVE-2026-18686
A remote command injection vulnerability affects GL.iNet GL-MT3000 devices up to version 4.4.5.- Applies to GL.iNet GL-MT3000 devices running firmware versions 4.4.0 through 4.4.5
- Vulnerability exists in nas-web.add_user function of /cgi-bin/glc component
- Allows unauthenticated remote attackers to perform command injection
- Exploit code is publicly available and confirmed by the vendor
- Severity rated critical with CVSS scores up to 9.8
๐ Coverage: cve.threatint.com ยท ๐ Original: cve.threatint.com ยท ๐ via CVE ThreatInt
๐ CVEs & KEV
- CVE-2026-11835 โ CVSS โ โ Caliptra Update-Reset Secure-Boot Bypass via Attacker-Chosen AXI Staging Addr...
- CVE-2026-11836 โ CVSS โ โ Production Debug-Unlock Token Verification Missing Device BindingInsufficient...