{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-18613","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2026-08-03T07:33:21.492Z","datePublished":"2026-08-03T17:45:09.762Z","dateUpdated":"2026-08-03T21:19:17.133Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2026-08-03T17:45:09.762Z"},"title":"GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-74","lang":"en","description":"Injection"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-707","lang":"en","description":"Improper Neutralization"}]}],"affected":[{"vendor":"GL-iNet","product":"GL-MT3000","versions":[{"version":"4.4.0","status":"affected"},{"version":"4.4.1","status":"affected"},{"version":"4.4.2","status":"affected"},{"version":"4.4.3","status":"affected"},{"version":"4.4.4","status":"affected"},{"version":"4.4.5","status":"affected"}],"cpes":["cpe:2.3:o:gl-inet:gl-mt3000_firmware:*:*:*:*:*:*:*:*"],"modules":["plugins.so Native Plugin"]}],"descriptions":[{"lang":"en","value":"A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the component plugins.so Native Plugin. Such manipulation leads to injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":9.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P","baseSeverity":"CRITICAL"}},{"cvssV3_1":{"version":"3.1","baseScore":9.8,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R","baseSeverity":"CRITICAL"}},{"cvssV3_0":{"version":"3.0","baseScore":9.8,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R","baseSeverity":"CRITICAL"}},{"cvssV2_0":{"version":"2.0","baseScore":10,"vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:C"}}],"timeline":[{"time":"2026-08-03T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2026-08-03T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2026-08-03T09:38:45.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"strforexc (VulDB User)","type":"reporter"},{"lang":"en","value":"VulDB CNA Team","type":"coordinator"}],"references":[{"url":"https://vuldb.com/vuln/385533","name":"VDB-385533 | GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/385533/cti","name":"VDB-385533 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-18613","name":"CVE-2026-18613 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/851557","name":"Submit #851557 | GL-iNet MT3000 4.4.5 Feed Hijacking","tags":["third-party-advisory"]},{"url":"https://github.com/StrTzz123/iot_vul/blob/main/GL-iNet/MT3000/4.4.5/plugins_set_config_glc_write/CVE.md","tags":["exploit"]}],"x_generator":["VulDB PVTS v202608"]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-03T21:16:38.795979Z","id":"CVE-2026-18613","options":[{"Exploitation":"poc"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-03T21:19:17.133Z"}}]}}