CVE-2026-26791: Command Injection
Published Mar 12, 2026
·Updated
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enableechoserver function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.
Affected Software
3 affected components
gl-inet GL-AR300M16
All of the following
gl-inet Ar300m16 Firmware=4.3.11
gl-inet AR300M16
Event History
Mar 12, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-26791?
CVE-2026-26791 is classified as a high severity command injection vulnerability.
2
How do I fix CVE-2026-26791?
To fix CVE-2026-26791, update the GL-iNet GL-AR300M16 firmware to a version newer than 4.3.11.
3
What does CVE-2026-26791 allow an attacker to do?
CVE-2026-26791 allows attackers to execute arbitrary commands on the affected device via crafted input.
4
Which software versions are affected by CVE-2026-26791?
CVE-2026-26791 affects GL-iNet GL-AR300M16 running firmware version 4.3.11.
5
How can I check if my device is vulnerable to CVE-2026-26791?
You can check if your device is vulnerable to CVE-2026-26791 by verifying that it is running GL-iNet GL-AR300M16 firmware version 4.3.11.