Executive brief
GL-iNet GL-MT3000 is a portable WiFi router used for secure remote connectivity and VPN access. A command injection vulnerability in the WireGuard configuration component allows remote attackers to execute arbitrary commands on the device by manipulating the private key parameter, potentially compromising the entire network infrastructure and connected devices.
Technical details
A command injection vulnerability exists in the wg-server.generate_publickey function within the wg-server.so native plugin, accessible via the /cgi-bin/glc endpoint. The vulnerability stems from insufficient input validation on the private_key argument, allowing an attacker to inject shell commands that are executed with device privileges. The attack is remotely exploitable without authentication, and the exploit code has been publicly disclosed. GL-iNet has confirmed the vulnerability exists in firmware versions up to 4.4.5.
Affected products
- GL-iNet GL-MT3000 up to 4.4.5
Timeline
- 2026-08-03: disclosed: Publicly disclosed vulnerability
- 2026-08-03: advisory: CVE-2026-18615 published