


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the component ovpn-cl…
Published:
2 augustus 2026 om 22:00:00
Alert date:
3 augustus 2026 om 15:06:10
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure, Zero-Day Vulnerabilities
A command injection vulnerability (CVE-2026-18601) has been identified in GL.iNet GL-MT3000 routers running firmware up to version 4.4.5. The vulnerability exists in the ovpn-client.check_config function within the /cgi-bin/glc file of the ovpn-client.so Native Plugin component. An attacker can exploit this by manipulating the 'filename' argument to inject arbitrary OS commands. The vulnerability is remotely exploitable without physical access to the device. A public exploit has already been released, increasing the risk of active exploitation. The vendor was notified prior to disclosure and has confirmed the vulnerability exists. This poses a significant risk to users of affected GL.iNet MT3000 devices, particularly those exposed to the internet.
Technical details
Mitigation steps:
Affected products:
GL.iNet GL-MT3000 firmware up to 4.4.5
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18601
https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/ovpn_check_config_glc_rce/CVE.md
https://vuldb.com/cve/CVE-2026-18601
https://vuldb.com/submit/851540
https://vuldb.com/vuln/385516
https://vuldb.com/vuln/385516/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
