CVE-2026-26793: Command Injection
Published Mar 12, 2026
·Updated
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the setconfig function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.
Affected Software
3 affected components
gl-inet GL-AR300M16
All of the following
gl-inet Ar300m16 Firmware=4.3.11
gl-inet AR300M16
Event History
Mar 12, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-26793?
CVE-2026-26793 is considered a high-severity vulnerability due to its potential for remote command execution.
2
How do I fix CVE-2026-26793?
To mitigate CVE-2026-26793, update the GL-iNet GL-AR300M16 to the latest firmware version that addresses this vulnerability.
3
Who is affected by CVE-2026-26793?
The CVE-2026-26793 vulnerability affects devices running GL-iNet GL-AR300M16 firmware version 4.3.11.
4
What is the nature of the vulnerability in CVE-2026-26793?
CVE-2026-26793 is a command injection vulnerability that allows attackers to execute arbitrary commands through the set_config function.
5
When was CVE-2026-26793 discovered?
CVE-2026-26793 was discovered in the GL-iNet GL-AR300M16 v4.3.11 firmware.