Vulnerabilities & Exploits · Web App Attack

Public PoCs Turn GL-MT3000 Bugs Into Edge Footholds

Public proof-of-concepts turn four GL-MT3000 bugs into easy entry points on a device that sits at the edge of a small network. The first thing that breaks is the router’s trust in normal settings fields; a crafted value can make it run attacker-chosen commands instead of saving a configuration change.

CSIRT Italia says the exposed flaws are CVE-2026-18601, CVE-2026-18602, CVE-2026-18612, and CVE-2026-18616. Three are command-injection bugs tied to uncleaned input such as filename, Hostname, and public_key, and all four are rated CVSS 9.8. The affected build line is GL-iNet GL-MT3000 4.4.x, version 4.4.5 and earlier.

The practical risk is bigger than one compromised appliance. If the gateway at the edge falls, the attacker is already inside the network it fronts, with a path to other SOHO or small-business systems behind it.

1 source · Aug 4

CVE-2026-18612

NVD KEV

CVSS 9.8 CRITICAL: a flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. EPSS 4% (90th percentile).

CVE-2026-18601

NVD KEV

CVSS 9.8 CRITICAL: a vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. EPSS 4% (89th percentile).

CVE-2026-18602

NVD KEV

CVSS 9.8 CRITICAL: a vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. EPSS 4% (89th percentile).

CVE-2026-18616

NVD KEV

CVSS 9.8 CRITICAL: a vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. EPSS 4% (89th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-08-04

Every edition of this story: Public PoCs Turn GL-MT3000 Bugs Into Edge Footholds

More from today