Command Injection Vulnerabilities in GL-iNet GL-AR300M16 Router
CVE-2026-26792

9.8CRITICAL

Key Information:

Vendor

GL-iNet

Vendor
CVE Published:
12 March 2026

What is CVE-2026-26792?

The GL-iNet GL-AR300M16 router version 4.3.11 has been found to have several command injection vulnerabilities within the 'set_upgrade' function. This weakness stems from improper input validation in the parameters: modem_url, target_version, current_version, firmware_upload, hash_type, hash_value, and upgrade_type. Malicious actors can exploit these vulnerabilities by sending specially crafted requests, leading to the execution of arbitrary commands on the affected device, which may compromise the integrity and security of the system.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.