
💉 PoC exists: CVE-2026-18686 hits GL.iNet GL-MT3000 via command injection in the nas-web.add_user function at /cgi-bin/glc. No auth needed, network-accessible, CVSS 8.9. Up to v4.4.5 affected. #cybersecurity #vulnerabilities #ciso https://secalerts.co/vulnerability/CVE-2026-18686?utm_campaign=x https://t.co/cWRYGNwVCD
Post summary
The tweet announces a PoC for CVE‑2026‑18686, describing a command‑injection flaw in the GL.iNet GL‑MT3000 (up to v4.4.5) with a CVSS score of 8.9.

