CVE-2026-18685: GL.iNet GL-MT3000 modem.so glc set_upgrade command injection
A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function setupgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18685?
CVE-2026-18685 has a critical severity rating of 9.8.
How does the CVE-2026-18685 vulnerability occur?
CVE-2026-18685 vulnerability occurs due to command injection in the set_upgrade function of the modem.so component.
Which devices are affected by CVE-2026-18685?
CVE-2026-18685 affects the GL.iNet GL-MT3000 modem up to version 4.4.5.
How can I mitigate CVE-2026-18685?
To mitigate CVE-2026-18685, upgrade to a patched version of the GL.iNet GL-MT3000 modem firmware.
Is it possible to exploit CVE-2026-18685 remotely?
Yes, CVE-2026-18685 can be exploited remotely, allowing attackers to execute arbitrary commands.