CVE-2026-18616: GL-iNet GL-MT3000 wg-server.so Native Plugin glc server.set_peer command injection
A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.setpeer of the file /cgi-bin/glc of the component wg-server.so Native Plugin. The manipulation of the argument publickey leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18616?
The severity of CVE-2026-18616 is critical, with a score of 9.8.
How do I fix CVE-2026-18616?
To fix CVE-2026-18616, update the GL-iNet GL-MT3000 and the wg-server.so Native Plugin to version 4.4.6 or later.
What causes CVE-2026-18616?
CVE-2026-18616 is caused by improper handling of the public_key argument in the server.set_peer function, leading to command injection vulnerabilities.
Who is affected by CVE-2026-18616?
Users of GL-iNet GL-MT3000 running versions up to 4.4.5 are affected by CVE-2026-18616.
Is CVE-2026-18616 exploitable remotely?
Yes, CVE-2026-18616 is remotely exploitable.