
🔌 GL.iNet GL-MT3000 up to 4.4.5 has a command injection flaw in ovpn-client.get_recommend_config via /cgi-bin/glc. No auth needed, network exploitable, CVSS 8.9. CVE-2026-18602 #cybersecurity #ciso #vulnerabilities #mssp https://secalerts.co/vulnerability/CVE-2026-18602?utm_campaign=x https://t.co/mmftCkOMe3
Post summary
The tweet announces a command injection vulnerability (CVE-2026-18602) affecting GL.iNet GL-MT3000 devices up to firmware 4.4.5, noting lack of authentication and network exploitation, without detailing PoC, exploits, patches, or active attacks.

