CVE-2026-18585: GL.iNet MT2500 APPS-NAS nas-web.get_file_list heap-based overflow
A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. The affected element is the function nas-web.getfilelist of the component APPS-NAS Module. Performing a manipulation results in heap-based buffer overflow. The attack may be initiated remotely. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18585?
CVE-2026-18585 has a medium severity rating of 4.3.
How do I fix CVE-2026-18585?
To fix CVE-2026-18585, update your GL.iNet device software to the latest version released after 20260707.
What types of devices are affected by CVE-2026-18585?
CVE-2026-18585 affects various GL.iNet devices including MT3000, MT6000, BE9300, BE3600, and others.
What is the nature of the vulnerability in CVE-2026-18585?
CVE-2026-18585 is a heap-based buffer overflow vulnerability found in the nas-web.get_file_list function.
What is the potential impact of CVE-2026-18585?
The potential impact of CVE-2026-18585 includes unauthorized access and manipulation of the affected device.