CVE-2026-18599 | GL.iNet GL-MT3000 up to 4.4.5 Logread Lua RPC Plugin logread logread.set_config record_size command injection

SecurityVulns

A vulnerability identified as critical has been detected in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC Plugin. This manipulation of the argument record_size causes command injection.

This vulnerability appears as CVE-2026-18599. The attacker needs to be present on the local network. In addition, an exploit is available.

The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.VulDB Recent EntriesRead More