CVE-2026-26795: Command Injection
Published Mar 12, 2026
·Updated
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.getsystemlog function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.
Affected Software
3 affected components
gl-inet GL-AR300M16
All of the following
gl-inet Ar300m16 Firmware=4.3.11
gl-inet AR300M16
Event History
Mar 12, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-26795?
CVE-2026-26795 is considered a high-severity vulnerability due to its potential for remote command execution.
2
How do I fix CVE-2026-26795?
To fix CVE-2026-26795, update the GL-iNet GL-AR300M16 firmware to a version that addresses this vulnerability.
3
What kind of vulnerability is CVE-2026-26795?
CVE-2026-26795 is a command injection vulnerability that allows attackers to execute arbitrary commands.
4
Which devices are affected by CVE-2026-26795?
CVE-2026-26795 affects the GL-iNet GL-AR300M16 running firmware version 4.3.11.
5
Can CVE-2026-26795 be exploited remotely?
Yes, CVE-2026-26795 can be exploited remotely by submitting crafted input to the affected system.