CVE-2026-18602Disclosure

LOW

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

1.5/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-04: 2PoC Mentioned / Linked · 2026-08-04: 1Technical Details · 2026-08-04: 208-04
Signal classification2 categories
Disclosure
150.0%
PoC
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • SecAlerts@SecAlertsCo
    Disclosure

    🔌 GL.iNet GL-MT3000 up to 4.4.5 has a command injection flaw in ovpn-client.get_recommend_config via /cgi-bin/glc. No auth needed, network exploitable, CVSS 8.9. CVE-2026-18602 #cybersecurity #ciso #vulnerabilities #mssp https://secalerts.co/vulnerability/CVE-2026-18602?utm_campaign=x https://t.co/mmftCkOMe3

    Post summary

    The tweet announces a command injection vulnerability (CVE-2026-18602) affecting GL.iNet GL-MT3000 devices up to firmware 4.4.5, noting lack of authentication and network exploitation, without detailing PoC, exploits, patches, or active attacks.

    01030416
    888 followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: #GL-iNet: PoC pubblici per lo sfruttamento delle CVE-2026-18601, CVE-2026-18602, CVE-2026-18612, CVE-2026-18616 Rischio: 🔴 Tipologia: 🔸Remote Code Execution 🔗https://www.acn.gov.it/portale/en/w/gl-inet-poc-pubblici-per-lo-sfruttamento-delle-cve-2026-18601-cve-2026-18602-cve-2026-18612-cve-2026-18616 🔄 Aggiornamenti disponibili 🔄 https://t.co/hyI0AfGXoC

    Post summary

    The post announces publicly available PoC code for four GL‑iNet RCE vulnerabilities (CVE‑2026‑18601, 18602, 18612, 18616) and provides a link to the details.

    0101168
    629 followersView on X

Explore more