GL.iNet CVEs

46 CVEs found for GL.iNet (last 12 months). Search terms: GL.iNet, GL-iNet.

Showing 26–46 of 46

CVE ID Severity CVSS Published Description
CVE-2026-11451 HIGH 7.3 2026-06-07 A flaw has been found in GL.iNet GL-MT3000 4.4.5. This impacts the function snprintf of the file /cgi-bin/glc of the component FTP Protocol Handler. Executing a manipulatio…
CVE-2026-11450 HIGH 7.3 2026-06-07 A vulnerability was detected in GL.iNet GL-MT3000 4.4.5. This affects the function dlopen in the library /usr/lib/oui-httpd/rpc/ of the component Path Normalization Handler…
CVE-2026-11449 MEDIUM 6.3 2026-06-07 A security vulnerability has been detected in GL.iNet GL-MT3000 4.4.5. The impacted element is the function rpc_sys of the file /cgi-bin/luci/rpc of the component LuCI JSON…
CVE-2026-11448 MEDIUM 4.7 2026-06-07 A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function realpath of the file /rpc of the component Minidlna Service. This mani…
CVE-2026-11447 MEDIUM 6.3 2026-06-07 A security flaw has been discovered in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function iwinfo_backend of the file iwinfo.so of the component MTK Backend. The manipu…
CVE-2026-11406 MEDIUM 6.3 2026-06-06 A vulnerability was determined in GL.iNet MT3000 up to 4.4.5. This vulnerability affects unknown code of the file ovpnclient.sh of the component OpenVPN Client Import Workf…
CVE-2023-46453 CRITICAL 9.8 2026-05-08 Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username that is both a valid SQL statement …
CVE-2026-5959 MEDIUM 6.6 2026-04-09 A security flaw has been discovered in GL.iNet GL-RM1, GL-RM10, GL-RM10RC and GL-RM1PE 1.8.1. Affected by this issue is some unknown functionality of the component Factory …
CVE-2026-32293 LOW 3.7 2026-03-17 The GL-iNet Comet (GL-RM1) KVM connects to a GL-iNet site during boot-up to provision client and CA certificates. The GL-RM1 does not verify certificates used for this conn…
CVE-2026-32292 HIGH 7.5 2026-03-17 The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess credentials.
CVE-2026-32291 MEDIUM 6.8 2026-03-17 The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requires physically opening the device and connecting to…
CVE-2026-32290 MEDIUM 4.7 2026-03-17 The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 does not sufficiently verify the authenticity of uploaded firmware files. An attacker-in-the-middle or a compromised upd…
CVE-2026-26793 CRITICAL 9.8 2026-03-12 GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. This vulnerability allows attackers to execute arbitrar…
CVE-2026-26795 CRITICAL 9.8 2026-03-12 GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. This vulnerability allows…
CVE-2026-26794 HIGH 8.8 2026-03-12 GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This vulnerability allows attackers to execute arbitrary S…
CVE-2026-26792 CRITICAL 9.8 2026-03-12 GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, target_version, current_vers…
CVE-2026-26791 CRITICAL 9.8 2026-03-12 GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server function. This vulnerability…
CVE-2025-67091 MEDIUM 6.5 2026-01-08 An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL.iNet custom opkg wrapper script located at /usr/libe…
CVE-2025-67090 MEDIUM 5.1 2026-01-08 The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL.Inet AX1800 Version 4.6.4 & 4.6.8 lacks rate limiti…
CVE-2025-67089 HIGH 8.1 2026-01-08 A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_package` RPC method, which f…
CVE-2025-44018 HIGH 8.3 2025-11-24 A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially crafted .tar file can lead to a firmware downgrade. An at…