CVE-2026-18600

HIGH

GL.iNet GL-MT3000 Network Lua RPC Plugin network network.switch_status command injection

Title source: cna
STIX 2.1

Description

A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.switch_status of the file /usr/lib/oui-httpd/rpc/network of the component Network Lua RPC Plugin. Such manipulation of the argument switch leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

References (5)

Core 5
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-385515 | GL.iNet GL-MT3000 Network Lua RPC Plugin network network.switch_status command injection
https://vuldb.com/vuln/385515
Signature, Permissions Required signature permissions-required
VDB-385515 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/385515/cti
Third Party Advisory third-party-advisory
CVE-2026-18600 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-18600
Third Party Advisory third-party-advisory
Submit #851537 | GL.iNet GL-MT3000 4.4.5 Command Injection
https://vuldb.com/submit/851537

Scores

CVSS v3 8.8
EPSS 0.0198
EPSS Percentile 78.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-74 CWE-77
Status published
Products (6)
GL.iNet/GL-MT3000 4.4.0
GL.iNet/GL-MT3000 4.4.1
GL.iNet/GL-MT3000 4.4.2
GL.iNet/GL-MT3000 4.4.3
GL.iNet/GL-MT3000 4.4.4
GL.iNet/GL-MT3000 4.4.5
Published Aug 03, 2026
Tracked Since Aug 03, 2026