Executive brief
A security vulnerability exists in the GL.iNet GL-MT3000 wireless router that could allow an attacker to take control of the device. By sending a specially crafted password update request, a remote attacker can execute unauthorized commands on the router. This could lead to a complete compromise of the device, potentially allowing attackers to intercept network traffic or disrupt internet services.
Technical details
A command injection vulnerability exists in the GL.iNet GL-MT3000 router within the SET_USER_PWD handler of the /cgi-bin/glc component. The vulnerability is located in function FUN_0042e200 and stems from improper neutralization of special elements in the 'Password' argument. An unauthenticated remote attacker can exploit this by submitting a password containing shell metacharacters (such as backticks or command substitution syntax), which are then executed by the underlying system shell. While the vendor notes that newer versions attempt to escape single quotes, versions up to 4.4.5 remain vulnerable to command substitution. The issue is addressed in firmware version 4.8.1.
Affected products
- GL.iNet GL-MT3000 up to 4.4.5
Timeline
- 2026-06-07: disclosed
- 2026-06-07: advisory: NVD publication date