CVE-2026-18684Patch

LOWCVSS 8.9 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-06: 1Patch / Workaround · 2026-08-06: 1Technical Details · 2026-08-06: 108-06
Signal classification1 categories
Patch
1100.0%
Referenced assets2 URLs
By indicator
Full discourse1 post
  • SecAlerts@SecAlertsCo
    Patch

    📡 GL.iNet GL-MT3000 up to 4.4.5: command injection via remove_profile in /cgi-bin/glc (http://modem.so). No auth, network-reachable, CVSS 8.9. CVE-2026-18684 — patch your firmware. #cybersecurity #ciso #cto #vulnerabilities #msp https://secalerts.co/vulnerability/CVE-2026-18684?utm_campaign=x https://t.co/mAWqGUKpil

    Post summary

    The GL.iNet GL‑MT3000 firmware up to 4.4.5 contains a command injection vulnerability (CVE‑2026‑18684) that requires patching.

    00000179
    876 followersView on X

Explore more