GL.iNet CVEs
46 CVEs found for GL.iNet (last 12 months). Search terms: GL.iNet, GL-iNet.
Showing 26–46 of 46
| CVE ID | Severity | CVSS | Published ↓ | Description |
|---|---|---|---|---|
| CVE-2026-11451 | HIGH | 7.3 | 2026-06-07 | A flaw has been found in GL.iNet GL-MT3000 4.4.5. This impacts the function snprintf of the file /cgi-bin/glc of the component FTP Protocol Handler. Executing a manipulatio… |
| CVE-2026-11450 | HIGH | 7.3 | 2026-06-07 | A vulnerability was detected in GL.iNet GL-MT3000 4.4.5. This affects the function dlopen in the library /usr/lib/oui-httpd/rpc/ of the component Path Normalization Handler… |
| CVE-2026-11449 | MEDIUM | 6.3 | 2026-06-07 | A security vulnerability has been detected in GL.iNet GL-MT3000 4.4.5. The impacted element is the function rpc_sys of the file /cgi-bin/luci/rpc of the component LuCI JSON… |
| CVE-2026-11448 | MEDIUM | 4.7 | 2026-06-07 | A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function realpath of the file /rpc of the component Minidlna Service. This mani… |
| CVE-2026-11447 | MEDIUM | 6.3 | 2026-06-07 | A security flaw has been discovered in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function iwinfo_backend of the file iwinfo.so of the component MTK Backend. The manipu… |
| CVE-2026-11406 | MEDIUM | 6.3 | 2026-06-06 | A vulnerability was determined in GL.iNet MT3000 up to 4.4.5. This vulnerability affects unknown code of the file ovpnclient.sh of the component OpenVPN Client Import Workf… |
| CVE-2023-46453 | CRITICAL | 9.8 | 2026-05-08 | Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username that is both a valid SQL statement … |
| CVE-2026-5959 | MEDIUM | 6.6 | 2026-04-09 | A security flaw has been discovered in GL.iNet GL-RM1, GL-RM10, GL-RM10RC and GL-RM1PE 1.8.1. Affected by this issue is some unknown functionality of the component Factory … |
| CVE-2026-32293 | LOW | 3.7 | 2026-03-17 | The GL-iNet Comet (GL-RM1) KVM connects to a GL-iNet site during boot-up to provision client and CA certificates. The GL-RM1 does not verify certificates used for this conn… |
| CVE-2026-32292 | HIGH | 7.5 | 2026-03-17 | The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess credentials. |
| CVE-2026-32291 | MEDIUM | 6.8 | 2026-03-17 | The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requires physically opening the device and connecting to… |
| CVE-2026-32290 | MEDIUM | 4.7 | 2026-03-17 | The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 does not sufficiently verify the authenticity of uploaded firmware files. An attacker-in-the-middle or a compromised upd… |
| CVE-2026-26793 | CRITICAL | 9.8 | 2026-03-12 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. This vulnerability allows attackers to execute arbitrar… |
| CVE-2026-26795 | CRITICAL | 9.8 | 2026-03-12 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. This vulnerability allows… |
| CVE-2026-26794 | HIGH | 8.8 | 2026-03-12 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This vulnerability allows attackers to execute arbitrary S… |
| CVE-2026-26792 | CRITICAL | 9.8 | 2026-03-12 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, target_version, current_vers… |
| CVE-2026-26791 | CRITICAL | 9.8 | 2026-03-12 | GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server function. This vulnerability… |
| CVE-2025-67091 | MEDIUM | 6.5 | 2026-01-08 | An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL.iNet custom opkg wrapper script located at /usr/libe… |
| CVE-2025-67090 | MEDIUM | 5.1 | 2026-01-08 | The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL.Inet AX1800 Version 4.6.4 & 4.6.8 lacks rate limiti… |
| CVE-2025-67089 | HIGH | 8.1 | 2026-01-08 | A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_package` RPC method, which f… |
| CVE-2025-44018 | HIGH | 8.3 | 2025-11-24 | A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially crafted .tar file can lead to a firmware downgrade. An at… |
Learn how grades are calculated: Grading Methodology