Heap-Based Buffer Overflow in GL.iNet Router Models
CVE-2026-18585
5.3MEDIUM
What is CVE-2026-18585?
A heap-based buffer overflow vulnerability exists in the GL.iNet routers, specifically within the nas-web.get_file_list function of the APPS-NAS Module. This vulnerability allows an attacker to manipulate the system, potentially leading to unauthorized access and denial of service. The flaw can be exploited remotely, making affected models susceptible if proper security measures are not taken. The vendor has been notified about this issue and is confirming its existence.
Affected Version(s)
BE3600 20260707
BE6500 20260707
BE9300 20260707
