Record summary

CVE-2026-18686 has a selected CVSS score of 9.3 (critical).

Description

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 4, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List4.4.0affected
4.4.1affected
4.4.2affected
4.4.3affected
4.4.4affected
4.4.5affected

Research & analysis

1
Technical researchValters ITSource: EIP research review

CVE-2026-18686 | GL.iNet | Valters IT Hub

Technical analysis of an unauthenticated command injection vulnerability in the GL.iNet GL-MT3000 travel router (firmware up to 4.4.5). The flaw resides in the nas-web.add_user function of the /cgi-bin/glc CGI endpoint within the nas-web RPC wrapper. The affected code path fails to sanitize user-supplied input in the username parameter, which is concatenated directly into a system command invocation without shell escaping. The function is reachable without authentication because the glc wrapper fails to enforce session validation for this RPC method. Commands execute as root. A corroborating advisory (IONIX) describes the injection as a two-stage second-order path through nas-web.add_share. Public exploit code is available. The writeup includes Sigma, YARA, Suricata, Elastic, Splunk, and Wazuh detection rules plus mitigation guidance. The source states the vulnerability is unpatched as of 2026-08-04; GL.iNet's public firmware page lists version 4.8.1 for this model, which may postdate the writeup.

Root causeTechnical detailPoC researchDetection
https://www.valtersit.com/cve/CVE-2026-18686
Research notes

References

5