CVE-2025-67089

HIGH

GL-iNet GL-AXT1800 Firmware 4.6.8 - Authenticated Command Injection via plugins.install_package RPC Method

Title source: llm
STIX 2.1

Description

A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_package` RPC method, which fails to properly sanitize user input in package names. Authenticated attackers can exploit this to execute arbitrary commands with root privileges

Scores

CVSS v3 8.1
EPSS 0.0143
EPSS Percentile 69.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (3)
gl-inet/gl-axt1800_firmware 4.2.0
gl-inet/gl-axt1800_firmware 4.6.4
gl-inet/gl-axt1800_firmware 4.6.8
Published Jan 08, 2026
Tracked Since Feb 18, 2026