Junglewise Threat Intelligence

CVE-2026-11447: GL.iNet GL-MT3000 command injection in MTK Backend

CVE-2026-11447 · Severity: medium · CVSS 6.3 · Published 2026-06-07

Technologies: GL.iNet GL-MT3000. Vendors: GL.iNet.

Executive brief

A security vulnerability has been identified in the GL.iNet GL-MT3000 wireless router. This flaw allows an attacker to execute unauthorized commands on the device, which could lead to a complete takeover of the router, interception of network traffic, or disruption of internet services. Users are advised to upgrade to firmware version 4.7 to protect their devices.

Technical details

A command injection vulnerability exists in the GL.iNet GL-MT3000 router (firmware up to 4.4.5) within the iwinfo_backend function of the iwinfo.so library, part of the MTK Backend component. The issue stems from improper neutralization of the 'device' argument, allowing an attacker to inject malicious commands. While the attack can be executed remotely over the network, it requires low-level privileges (PR:L). Successful exploitation allows for arbitrary command execution on the underlying operating system. A public exploit has been released. The vendor has addressed this in version 4.7 by implementing global injection protection in the SDK.

Affected products

  • GL.iNet GL-MT3000 up to 4.4.5

Timeline

  • 2026-06-07: advisory: NVD publication date
  • 2026-06-07: disclosed: Public disclosure of the vulnerability and exploit

References

Related threats