CVE-2026-18600: Command Injection in GL.iNet GL-MT3000
A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.switch_status of the file /usr/lib/oui-httpd/rpc/network of the component Network Lua RPC Plugin. Such manipulation of the argument switch leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
AI Analysis
Technical Summary
This vulnerability in GL.iNet GL-MT3000 devices up to version 4.4.5 allows remote attackers to perform command injection via the 'switch' argument in the network.switch_info and network.switch_status functions of the Network Lua RPC Plugin. The affected component is located in /usr/lib/oui-httpd/rpc/network. The vendor has confirmed the vulnerability following early notification. The exploit details have been publicly disclosed, but no official patch or remediation level has been provided in the available data.
Potential Impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands remotely on the affected device, potentially leading to full compromise of the device. This can result in unauthorized control over network functions and device operations, posing significant security risks.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or temporary workaround is documented, users should monitor the vendor's communications for updates. Until a patch is available, restricting network access to the affected RPC interface may reduce exposure.
CVE-2026-18600: Command Injection in GL.iNet GL-MT3000
Description
A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.switch_status of the file /usr/lib/oui-httpd/rpc/network of the component Network Lua RPC Plugin. Such manipulation of the argument switch leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
CVSS v4.0
Score 8.7high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in GL.iNet GL-MT3000 devices up to version 4.4.5 allows remote attackers to perform command injection via the 'switch' argument in the network.switch_info and network.switch_status functions of the Network Lua RPC Plugin. The affected component is located in /usr/lib/oui-httpd/rpc/network. The vendor has confirmed the vulnerability following early notification. The exploit details have been publicly disclosed, but no official patch or remediation level has been provided in the available data.
Potential Impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary commands remotely on the affected device, potentially leading to full compromise of the device. This can result in unauthorized control over network functions and device operations, posing significant security risks.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or temporary workaround is documented, users should monitor the vendor's communications for updates. Until a patch is available, restricting network access to the affected RPC interface may reduce exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-08-03T06:55:19.221Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7098b0bf32cb7a34a822b2
Added to database: 08/03/2026, 13:33:36 UTC
Last enriched: 08/03/2026, 13:52:53 UTC
Last updated: 08/04/2026, 03:17:46 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.