github.comexploit
https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/logread_set_config_rpc_rce/CVE.md CVE-2026-18599
HIGH
GL.iNet GL-MT3000 Logread Lua RPC Plugin logread logread.set_config command injection
Record summary
CVE-2026-18599 has a selected CVSS score of 8.6 (high).
Description
A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC Plugin. This manipulation of the argument record_size causes command injection. The exploit has been published and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 3, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
GL-MT3000Browse GL.iNet / GL-MT3000 | CVE List | 4.4.0 | affected |
| 4.4.1 | affected | ||
| 4.4.2 | affected | ||
| 4.4.3 | affected | ||
| 4.4.4 | affected | ||
| 4.4.5 | affected |
References
6nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-18599 CVE-2026-18599 | CVE Analysis and ReportThird-party advisory
https://vuldb.com/cve/CVE-2026-18599 Submit #851536 | GL.iNet GL-MT3000 4.4.5 Command InjectionThird-party advisory
https://vuldb.com/submit/851536 VDB-385514 | GL.iNet GL-MT3000 Logread Lua RPC Plugin logread logread.set_config command injectionvdb entryTechnical description
https://vuldb.com/vuln/385514 VDB-385514 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/vuln/385514/cti