LiveActive security incident?Get immediate response
CVE Record

CVE-2026-18616: GL-iNet GL-MT3000 wg-server.so Native Plugin glc server.set_peer command injection

A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the component wg-server.so Native Plugin. The manipulation of the argument public_key leads to command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

CriticalCVSS 10Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

CVE-2026-18616 is a critical command-injection flaw in GL-iNet GL-MT3000 firmware versions 4.4.0 through 4.4.5. A remote attacker may abuse the WireGuard server plugin to execute system commands, potentially compromising the router’s confidentiality, integrity, and availability. Public exploit material exists, but active exploitation is not confirmed.

Executive priority

Treat this as an immediate investigation and remediation priority for affected routers, especially externally reachable devices. Successful exploitation could provide extensive control over a network-edge device. Public exploit availability increases near-term risk, although active attacks are not established. Obtain current vendor guidance and reduce interface exposure while assessing or applying remediation.

Technical view

The flaw affects server.set_peer in the wg-server.so native plugin, reached through /cgi-bin/glc. Improper handling of the public_key argument permits command injection, classified as CWE-74 and CWE-77. The supplied CVSS v2.0 score is 10.0 with network access, low complexity, and no authentication. The vendor reportedly confirmed the vulnerability.

Likely exposure

Exposure is limited to GL-iNet GL-MT3000 devices running firmware 4.4.0 through 4.4.5 where the affected WireGuard server plugin and /cgi-bin/glc interface are reachable. Internet-accessible or untrusted-network-reachable management interfaces present the greatest concern. The bundle does not establish whether default configurations expose the vulnerable path.

Exploitation context

A public proof of concept is referenced, demonstrating that exploitation knowledge is available. The source bundle says remote exploitation is possible and the exploit might be used. CVE-2026-18616 is not identified as a CISA KEV entry, and the supplied evidence does not confirm active exploitation.

Researcher notes

The evidence identifies the vulnerable function, file, parameter, affected versions, remote vector, and public proof of concept. It does not provide a vendor patch version, official workaround, default reachability analysis, or verified field exploitation. The severity uses CVSS v2.0 rather than a newer scoring version; validate organizational prioritization against deployment context.

Mitigation direction

  • Identify GL-MT3000 devices running firmware versions 4.4.0 through 4.4.5.
  • Restrict /cgi-bin/glc and router management access to trusted networks and administrators.
  • Disable the affected WireGuard server plugin if operationally acceptable.
  • Check GL-iNet guidance for patched firmware or vendor-approved remediation.
  • Prioritize replacement or isolation if no supported fix is available.

Validation and detection

  • Confirm each GL-MT3000 model and installed firmware version.
  • Determine whether wg-server.so and server.set_peer are present and enabled.
  • Verify whether /cgi-bin/glc is reachable from internet or untrusted networks.
  • Review relevant router and network logs for unexpected requests or command execution indicators.
  • After remediation, confirm the vulnerable interface is restricted or vendor-fixed firmware is installed.
Prepared
Confidence
high
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-74: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cwe · medium confidence lookup

CWE-77: Command execution behavior lookup

Command injection weaknesses can lead defenders to review execution techniques and command interpreter telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
description · low confidence lookup

Execution behavior lookup

The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-18616 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
10 (2.0)
Known Exploited
No
Published

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:C

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

4CVSS vectors
6Timeline events
1ADP providers
6Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: pocAutomatable: yesTechnical Impact: total

CVSS vector scores

4 official scores

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
10CVSS 2.0CriticalAV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:C1010VulDB
9.8CVSS 3.1CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R3.95.9VulDB
9.8CVSS 3.0CriticalCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R3.95.9VulDB
9.3CVSS 4.0CriticalCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:PVulDB

Vulnerability scoring details

Base CVSS 4.0 score

9.3Critical
CVSS 4.0 vector shape for CVE-2026-18616Attack VectorAttack ComplexityAttack RequirementsPrivileges RequiredUser InteractionVS ConfidentialityVS IntegrityVS AvailabilitySS ConfidentialitySS IntegritySS Availability

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Attack Requirements
NonePresent
Privileges Required
NoneLowHigh
User Interaction
NonePassiveActive
VS Confidentiality
HighLowNone
VS Integrity
HighLowNone
VS Availability
HighLowNone
SS Confidentiality
HighLowNone
SS Integrity
HighLowNone
SS Availability
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. Source timelineVulDB

    Advisory disclosed

  2. Source timelineVulDB

    VulDB entry created

  3. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  4. Source timelineVulDB

    VulDB entry last update

  5. CVE publishedCVE Program

    The CVE record was published.

  6. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
GL-iNetGL-MT30004.4.0, 4.4.1, 4.4.2, 4.4.3, 4.4.4, 4.4.5Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-74 · source CWE mapping

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.

CWE-77 · source CWE mapping

Improper Neutralization of Special Elements used in a Command ('Command Injection')

Improper Neutralization of Special Elements used in a Command ('Command Injection') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.