CVE-2026-18585 | GL.iNet MT2500 up to 20260707 APPS-NAS nas-web.get_file_list heap-based overflow

SecurityVulns

A vulnerability was found in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. It has been rated as critical. The affected element is the function nas-web.get_file_list of the component APPS-NAS Module. Performing a manipulation results in heap-based buffer overflow.

This vulnerability was named CVE-2026-18585. The attack may be initiated remotely. There is no available exploit.

The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.VulDB Recent EntriesRead More