Command Injection Vulnerability in GL-iNet GL-AR300M16
CVE-2026-26795
9.8CRITICAL
What is CVE-2026-26795?
A command injection vulnerability has been identified in the GL-iNet GL-AR300M16, specifically within the M.get_system_log function. This flaw permits remote attackers to execute arbitrary system commands by sending specially crafted input to the module parameter, potentially compromising the device’s integrity and security.
