
🔌 GL-iNet GL-MT3000 routers up to 4.4.5 are vulnerable to command injection via the server.set_peer function in http://wg-server.so. No auth needed over the network. CVE-2026-18616 | CVSS 8.9 #cybersecurity #vulnerabilities #ciso https://secalerts.co/vulnerability/CVE-2026-18616?utm_campaign=x https://t.co/3uNGyPYbYK
Post summary
GL‑iNet GL‑MT3000 routers (firmware up to 4.4.5) are vulnerable to unauthenticated command injection (CVE‑2026‑18616) via server.set_peer, with a PoC reference at wg‑server.so; no patch or active exploitation has been reported yet.


