CVE-2026-18613: GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection
A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.setconfig of the file /cgi-bin/glc of the component plugins.so Native Plugin. Such manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18613?
CVE-2026-18613 has a critical severity score of 9.8.
How do I fix CVE-2026-18613?
To fix CVE-2026-18613, update the GL-iNet GL-MT3000 to the latest version beyond 4.4.5.
What is affected by CVE-2026-18613?
CVE-2026-18613 affects the plugins.set_config function within the plugins.so Native Plugin on GL-iNet GL-MT3000 devices.
Can CVE-2026-18613 be exploited remotely?
Yes, CVE-2026-18613 can be exploited remotely.
What type of injection does CVE-2026-18613 involve?
CVE-2026-18613 involves injection through the manipulation of the plugins.set_config function.