Junglewise Threat Intelligence

CVE-2026-11448: GL.iNet GL-MT3000 command injection in MiniDLNA Service

CVE-2026-11448 · Severity: medium · CVSS 4.7 · Published 2026-06-07

Technologies: GL.iNet GL-MT3000. Vendors: GL.iNet.

Executive brief

A security vulnerability exists in GL.iNet GL-MT3000 routers that could allow an authorized administrator to take full control of the device. By sending a specially crafted request to the router's configuration service, an attacker can execute malicious commands with the highest system privileges (root). This could lead to complete device compromise, data interception, or disruption of network services.

Technical details

An authenticated command injection vulnerability exists in the MiniDLNA service of GL.iNet GL-MT3000 routers running firmware up to version 4.4.5. The issue stems from the /rpc endpoint allowing authenticated users with 'luci-base' scope to write arbitrary values to the 'minidlna.config.db_dir' UCI parameter. The init script fails to quote these values when writing to /var/etc/minidlna.conf. Subsequently, the minidlnad daemon (running as root) processes this unsanitized input through a system() call via snprintf when handling the db_dir configuration. An attacker can exploit this by injecting shell metacharacters into the db_dir argument to achieve remote code execution. The vendor has addressed this in version 4.7 by adding global injection protection.

Affected products

  • GL.iNet GL-MT3000 up to 4.4.5

Timeline

  • 2026-05-11: disclosed: Initial submission date
  • 2026-06-07: advisory: NVD publication date

References

Related threats