Command Injection Vulnerabilities in GL-iNet GL-AR300M16 Router
CVE-2026-26792
9.8CRITICAL
What is CVE-2026-26792?
The GL-iNet GL-AR300M16 router version 4.3.11 has been found to have several command injection vulnerabilities within the 'set_upgrade' function. This weakness stems from improper input validation in the parameters: modem_url, target_version, current_version, firmware_upload, hash_type, hash_value, and upgrade_type. Malicious actors can exploit these vulnerabilities by sending specially crafted requests, leading to the execution of arbitrary commands on the affected device, which may compromise the integrity and security of the system.
