CVE-2026-18686: GL.iNet GL-MT3000 nas-web RPC Wrapper glc nas-web.add_user command injection
A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.adduser of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18686?
CVE-2026-18686 has a critical severity rating of 9.8.
How do I fix CVE-2026-18686?
To fix CVE-2026-18686, update GL.iNet GL-MT3000 to version 4.4.6 or later.
What type of vulnerability is CVE-2026-18686?
CVE-2026-18686 is classified as a command injection vulnerability.
Can CVE-2026-18686 be exploited remotely?
Yes, CVE-2026-18686 can be exploited remotely through the affected nas-web RPC Wrapper.
What components are affected by CVE-2026-18686?
CVE-2026-18686 affects the nas-web.add_user function in the GL.iNet GL-MT3000.