CVE-2026-26792: Command Injection
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the setupgrade function via the modemurl, targetversion, currentversion, firmwareupload, hashtype, hashvalue, and upgradetype parameters. These vulnerabilities allow attackers to execute arbitrary commands via a crafted input.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26792?
CVE-2026-26792 has a high severity rating due to the potential for remote command injection.
How do I fix CVE-2026-26792?
To fix CVE-2026-26792, update GL-iNet GL-AR300M16 firmware to a version above v4.3.11 that addresses these vulnerabilities.
What are the affected versions in CVE-2026-26792?
The affected version in CVE-2026-26792 is GL-iNet GL-AR300M16 firmware version 4.3.11.
What type of attack is possible due to CVE-2026-26792?
CVE-2026-26792 allows attackers to execute arbitrary commands on the device via command injection.
Which function is vulnerable in CVE-2026-26792?
The vulnerable function in CVE-2026-26792 is the set_upgrade function.