Executive brief
GL-iNet GL-MT3000 is a wireless router used to provide internet connectivity and network management. A flaw in the WireGuard configuration function allows attackers to inject arbitrary system commands through the public key parameter, potentially gaining remote access to the device and compromising network security.
Technical details
The vulnerability is a command injection flaw in the server.set_peer function within the wg-server.so native plugin, accessible via /cgi-bin/glc. The public_key parameter is improperly sanitized, allowing an attacker to inject shell commands that are executed with device privileges. The attack is network-accessible without authentication requirements. An attacker can achieve remote code execution and complete compromise of the router. The vulnerability affects GL-MT3000 firmware up to version 4.4.5, and the vendor has been notified.
Affected products
- GL-iNet GL-MT3000 up to 4.4.5
Timeline
- 2026-08-03: disclosed