Junglewise Threat Intelligence

CVE-2026-11452: GL.iNet GL-MT3000 command injection in SET_USER_PWD handler

CVE-2026-11452 · Severity: high · CVSS 7.3 · Published 2026-06-07

Technologies: GL.iNet GL-MT3000. Vendors: GL.iNet.

Executive brief

A security vulnerability exists in the GL.iNet GL-MT3000 wireless router that could allow an attacker to take control of the device. By sending a specially crafted password update request, a remote attacker can execute unauthorized commands on the router. This could lead to a complete compromise of the device, potentially allowing attackers to intercept network traffic or disrupt internet services.

Technical details

A command injection vulnerability exists in the GL.iNet GL-MT3000 router within the SET_USER_PWD handler of the /cgi-bin/glc component. The vulnerability is located in function FUN_0042e200 and stems from improper neutralization of special elements in the 'Password' argument. An unauthenticated remote attacker can exploit this by submitting a password containing shell metacharacters (such as backticks or command substitution syntax), which are then executed by the underlying system shell. While the vendor notes that newer versions attempt to escape single quotes, versions up to 4.4.5 remain vulnerable to command substitution. The issue is addressed in firmware version 4.8.1.

Affected products

  • GL.iNet GL-MT3000 up to 4.4.5

Timeline

  • 2026-06-07: disclosed
  • 2026-06-07: advisory: NVD publication date

References

Related threats