Record summary

CVE-2026-18599 has a selected CVSS score of 8.6 (high).

Description

A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC Plugin. This manipulation of the argument record_size causes command injection. The exploit has been published and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 3, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List4.4.0affected
4.4.1affected
4.4.2affected
4.4.3affected
4.4.4affected
4.4.5affected

References

6
VDB-385514 | GL.iNet GL-MT3000 Logread Lua RPC Plugin logread logread.set_config command injectionvdb entryTechnical description
https://vuldb.com/vuln/385514