


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component n…
Published:
3 augustus 2026 om 22:00:00
Alert date:
4 augustus 2026 om 01:01:17
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure, Zero-Day Vulnerabilities
A command injection vulnerability has been identified in GL.iNet GL-MT3000 routers running firmware up to version 4.4.5. The flaw exists in the nas-web.add_user function within the /cgi-bin/glc file of the nas-web RPC Wrapper component. An attacker can remotely exploit this vulnerability by manipulating input to achieve command injection. A public exploit is already available, increasing the risk of active exploitation. The vendor was notified early in the disclosure process and confirmed the vulnerability's existence. This affects IoT/router hardware widely used in home and small office environments. The public availability of exploit code significantly elevates the risk level for unpatched devices.
Technical details
Mitigation steps:
Affected products:
GL.iNet GL-MT3000 up to 4.4.5
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18686
https://github.com/coconut652-7/IOT_Vul_Public/tree/main/Glinet/MT3000/nas-web/ADD_USER_ADD_SHARE
https://vuldb.com/cve/CVE-2026-18686
https://vuldb.com/submit/856139
https://vuldb.com/vuln/385612
https://vuldb.com/vuln/385612/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
