SQL Injection Vulnerability in GL-iNet GL-AR300M16 Router
CVE-2026-26794

8.8HIGH

Key Information:

Vendor

GL-iNet

Vendor
CVE Published:
12 March 2026

What is CVE-2026-26794?

A SQL injection vulnerability has been identified in the GL-iNet GL-AR300M16 version 4.3.11. This weakness resides in the add_group() function, which is susceptible to crafted HTTP requests that enable attackers to perform arbitrary SQL operations on the database. Successful exploitation of this vulnerability could lead to unauthorized access to database information, posing significant security risks for users of this IoT device.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.