CVE-2026-18612Patch

LOW

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

2.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-08-04: 4PoC Mentioned / Linked · 2026-08-04: 1Patch / Workaround · 2026-08-04: 2Technical Details · 2026-08-04: 408-04
Signal classification3 categories
Patch
250.0%
Disclosure
125.0%
PoC
125.0%
Referenced assets3 URLs
Full discourse4 posts
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: #GL-iNet: PoC pubblici per lo sfruttamento delle CVE-2026-18601, CVE-2026-18602, CVE-2026-18612, CVE-2026-18616 Rischio: 🔴 Tipologia: 🔸Remote Code Execution 🔗https://www.acn.gov.it/portale/en/w/gl-inet-poc-pubblici-per-lo-sfruttamento-delle-cve-2026-18601-cve-2026-18602-cve-2026-18612-cve-2026-18616 🔄 Aggiornamenti disponibili 🔄 https://t.co/hyI0AfGXoC

    Post summary

    The tweet alerts that public Proof‑of‑Concepts exist for four new CVE‑2026‑1860x vulnerabilities targeting GL‑iNet devices, enabling remote code execution, with a link to an ACN article for details.

    0101168
    629 followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    GL-iNet GL-MT3000 up to 4.4.5 is vulnerable to command injection via plugins.install_package in /cgi-bin/glc. No auth needed, network exploitable. CVE-2026-18612 🔌 #cybersecurity #ciso #vulnerabilities #msp https://secalerts.co/vulnerability/CVE-2026-18612?utm_campaign=x https://t.co/VQBfBt2cTG

    Post summary

    The tweet announces that the GL-iNet GL-MT3000 router firmware up to 4.4.5 is vulnerable to unauthenticated command injection via plugins.install_package, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    00020146
    888 followersView on X
  • ztg@ZeroTrustGhost
    Patch

    GL.iNet GL-MT3000 has an unpatched CVSS 9.8 command injection (CVE-2026-18612) with a public exploit. Disable remote management on those travel routers until a patch drops.

    Post summary

    The post warns of an unpatched command injection vulnerability (CVE-2026-18612) in GL.iNet routers and advises disabling remote management until a vendor patch is released.

    0000056
    93 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    CVE-2026-18612 - Critical command injection in GL.iNet GL-MT3000 (<=4.4.5). Remote exploit public, unpatched. CVSS 9.8. Disable remote management immediately. #CVE #GLiNet #infosec https://www.valtersit.com/cve/cve-2026-18612/ #CVE #Linux #infosec #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu

    Post summary

    The tweet discloses a critical command injection vulnerability (CVE‑2026‑18612) in GL.iNet routers, highlights a publicly available remote exploit with a CVSS score of 9.8, and recommends disabling remote management as a mitigation step.

    0000094
    1.0K followersView on X

Explore more