CVE-2026-18598 | GL.iNet GL-MT3000 up to 4.4.5 Logread Lua RPC plugin logread logread.get_system_log module command injection

SecurityVulns

A vulnerability categorized as critical has been discovered in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_log of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC plugin. The manipulation of the argument module results in command injection.

This vulnerability is reported as CVE-2026-18598. The attack can be launched remotely. Moreover, an exploit is present.

The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.VulDB Recent EntriesRead More