Junglewise Threat Intelligence

CVE-2026-12187: GL.iNet GL-MT3000 command injection in Online Firmware Upgrade Handler

CVE-2026-12187 · Severity: high · CVSS 8.8 · Published 2026-06-14

Technologies: GL.iNet GL-MT3000. Vendors: GL.iNet.

Executive brief

A security vulnerability exists in the GL.iNet GL-MT3000 wireless router, specifically within its firmware update mechanism. An attacker can remotely inject malicious commands into the device, potentially leading to a complete takeover of the router. This could allow an unauthorized user to intercept network traffic, disrupt internet connectivity, or use the device as a foothold for further attacks on the local network.

Technical details

A command injection vulnerability exists in the GL.iNet GL-MT3000 router within the '/usr/bin/one_click_upgrade' file, which is part of the Online Firmware Upgrade Handler component. The flaw stems from improper neutralization of special elements (CWE-74, CWE-77) during the processing of upgrade requests. A remote attacker with low-level privileges can exploit this by sending crafted inputs to the upgrade handler, leading to arbitrary command execution on the underlying operating system. The exploit has been disclosed publicly. Users are advised to upgrade to firmware version 4.7 or later to mitigate this risk.

Affected products

  • GL.iNet GL-MT3000 up to 4.4.5

Timeline

  • 2026-06-14: disclosed: Public disclosure of the vulnerability and exploit details.
  • 2026-06-14: advisory
  • 2026-06-14: patched: Vendor released version 4.7 to address the issue.

References

Related threats