GL.iNet Vulnerabilities and Affected Products
Vulnerabilities associated with XE3000.
Products
Clear product- GL-MT300016 vulnerabilities
- MT30005 vulnerabilities
- MT60005 vulnerabilities
- AX18004 vulnerabilities
- MT25004 vulnerabilities
- A13003 vulnerabilities
- AR300M3 vulnerabilities
- AXT18003 vulnerabilities
- GL-A1300 Slate Plus3 vulnerabilities
- GL-AR300M Shadow3 vulnerabilities
- GL-AR300M16 Shadow3 vulnerabilities
- GL-AR750 Creta3 vulnerabilities
- GL-AR750S-EXT Slate3 vulnerabilities
- GL-AX1800 Flint3 vulnerabilities
- GL-AXT1800 Slate AX3 vulnerabilities
- GL-B1300 Convexa-B3 vulnerabilities
- GL-B3000 Marble3 vulnerabilities
- GL-BE3600 Slate 73 vulnerabilities
- GL-E7503 vulnerabilities
- GL-E750V2 Mudi3 vulnerabilities
- GL-MT1300 Beryl3 vulnerabilities
- GL-MT2500 Brume 23 vulnerabilities
- GL-MT3000 Beryl AX3 vulnerabilities
- GL-MT300N-V2 Mango3 vulnerabilities
- GL-MT6000 Flint 23 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-18585MEDIUM | GL.iNet MT2500 APPS-NAS nas-web.get_file_list heap-based overflowA vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. The affected element is the function nas-web.get_file_list of the component APPS-NAS Module. Performing a manipulation results in heap-based buffer overflow. The attack may be initiated remotely. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. | CVSS5.3v4.0 | EPSS0.299% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-18584MEDIUM | GL.iNet E5800/E750/X2000/X3000/XE3000/XE300 eSIM LPA API v1 improper authorizationA security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of the file /sdk/v1 of the component eSIM LPA API. Such manipulation leads to improper authorization. The attack can only be initiated within the local network. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. | CVSS5.3v4.0 | EPSS0.23% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
GL.iNet XE3000 glnassys hard-coded keyA flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an unknown function of the component glnassys. Executing a manipulation can lead to use of hard-coded cryptographic key . The attack may be launched remotely. The attack requires a high level of complexity. The exploitability is reported as difficult. Upgrading to version 4.9.0 mitigates this issue. Upgrading the affected component is advised. | CVSS2.3v4.0 | EPSS0.197% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |