Junglewise Threat Intelligence

CVE-2026-18614: GL-iNet GL-MT3000 command injection in s2s.so

CVE-2026-18614 · Severity: critical · CVSS 9.8 · Published 2026-08-03

Technologies: GL.iNet GL-MT3000. Vendors: GL.iNet.

Executive brief

GL-iNet GL-MT3000 is a wireless router used for home and business networking. A remote attacker can inject arbitrary commands through the s2s echo server port parameter, potentially gaining full control of the device without authentication. This vulnerability affects versions up to 4.4.5 and has been publicly disclosed with working exploits available.

Technical details

The vulnerability is a command injection flaw in the s2s.so native plugin, specifically in the s2s.enable_echo_server function accessible via /cgi-bin/glc. The root cause is insufficient input validation on the port parameter, allowing an attacker to inject shell metacharacters and execute arbitrary system commands. The attack vector is remote and requires no authentication. An attacker can manipulate the port argument to execute commands with the privileges of the web server process, potentially achieving remote code execution and full device compromise. The vendor confirmed the vulnerability; patch status is not explicitly stated in the advisory.

Affected products

  • GL-iNet GL-MT3000 up to 4.4.5

Timeline

  • 2026-08-03: disclosed

References

Related threats