Executive brief
GL.iNet's BE9300 and MT6000 routers contain a firewall management vulnerability that allows remote attackers to execute arbitrary commands as root. An attacker can inject malicious commands through firewall configuration parameters, potentially gaining full control over the router, reading sensitive files, modifying network settings, and pivoting into connected networks.
Technical details
A command injection vulnerability exists in the firewall-management RPC component of GL.iNet BE9300 and MT6000 routers running firmware version 4.8.x. The vulnerability arises from insufficient input validation on firewall configuration parameters (dest_port and dest_ip), which accept newline characters that are later concatenated unsanitized into conntrack cleanup shell commands. An unauthenticated remote attacker can exploit this by sending crafted RPC requests with embedded shell metacharacters to achieve arbitrary command execution with root privileges. The attack requires network access to the router's management interface and does not require user interaction. A patch is available in firmware version 4.9.0 and later.
Affected products
- GL.iNet BE9300 4.8.x (fixed in 4.9.0)
- GL.iNet MT6000 4.8.x (fixed in 4.9.0)
Timeline
- 2026-08-17: disclosed: Public disclosure
- 2026: patched: Fix available in firmware version 4.9.0