Command Injection Vulnerability in GL.iNet GL-MT3000 Router
CVE-2026-11452
6.9MEDIUM
What is CVE-2026-11452?
A command injection vulnerability exists in the GL.iNet GL-MT3000 router's SET_USER_PWD Handler. The issue stems from improper handling of the password parameter in the function FUN_0042e200, which could allow attackers to execute arbitrary commands remotely. Users are advised to upgrade to version 4.8.1, which mitigates this vulnerability. The vendor confirms that this version addresses the issue by properly escaping command injection vectors.
Affected Version(s)
GL-MT3000 4.4.0
GL-MT3000 4.4.1
GL-MT3000 4.4.2
