Junglewise Threat Intelligence

CVE-2026-12186: GL.iNet GL-MT3000 command injection in Tor Proxy Service Configuration Handler

CVE-2026-12186 · Severity: high · CVSS 8.8 · Published 2026-06-14

Technologies: GL.iNet GL-MT3000. Vendors: GL.iNet.

Executive brief

A security vulnerability exists in the GL.iNet GL-MT3000 router, a device used for providing wireless internet and VPN services. An attacker can remotely inject malicious commands into the device's Tor proxy configuration handler. If exploited, this could allow an attacker to take full control of the router, potentially leading to data interception, service disruption, or unauthorized access to the local network.

Technical details

A command injection vulnerability exists in the GL.iNet GL-MT3000 router firmware up to version 4.4.5. The flaw is located within the 'replace_country' function in the '/usr/lib/oui-httpd/rpc/tor' library, which serves as the Tor Proxy Service Configuration Handler. The vulnerability is caused by improper neutralization of special elements in user-supplied input. A remote attacker with low privileges can exploit this by sending crafted requests to the RPC interface, leading to arbitrary command execution on the underlying operating system. Public exploit code is available. The issue is addressed in firmware version 4.7 and later.

Affected products

  • GL.iNet GL-MT3000 up to 4.4.5

Timeline

  • 2026-06-14: disclosed
  • 2026-06-14: advisory
  • 2026-06-14: patched: Vendor released fix in version 4.7

References

Related threats