{"id":79411,"date":"2026-06-07T07:46:29","date_gmt":"2026-06-07T04:16:29","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2026-11452-gl-inet-gl-mt3000-set_user_pwd-glc-fun_0042e200-command-injection\/"},"modified":"2026-06-07T07:46:29","modified_gmt":"2026-06-07T04:16:29","slug":"cve-2026-11452-gl-inet-gl-mt3000-set_user_pwd-glc-fun_0042e200-command-injection","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2026-11452-gl-inet-gl-mt3000-set_user_pwd-glc-fun_0042e200-command-injection\/","title":{"rendered":"CVE-2026-11452 &#8211; GL.iNet GL-MT3000 SET_USER_PWD glc FUN_0042e200 command injection"},"content":{"rendered":"<p>CVE ID :CVE-2026-11452<\/p>\n<p>  Published : June 7, 2026, 4:16 a.m. | 16\u00a0minutes ago<\/p>\n<p>  Description :A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function FUN_0042e200 of the file \/cgi-bin\/glc of the component SET_USER_PWD Handler. The manipulation of the argument Password leads to command injection. The attack can be initiated remotely. Upgrading to version 4.8.1 is able to address this issue. The affected component should be upgraded. The vendor explains: &#8221; The current code escapes single quotes in the password parameter and handles it inside a shell single\u2011quote context. The payloads in the report, which rely on $() or backticks to trigger command substitution, are not executed under the current code path. We tested on a GL\u2011MT3000 device running firmware 4.8.1 using similar payloads, and no command\u2011execution marker file was created.&#8221;<\/p>\n<p>  Severity: 7.5 | HIGH<\/p>\n<p>  Visit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID :CVE-2026-11452 Published : June 7, 2026, 4:16 a.m. | 16\u00a0minutes ago Description :A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function FUN_0042e200 of the file \/cgi-bin\/glc of the component SET_USER_PWD Handler. The manipulation of the argument Password leads to command injection. The attack can be initiated remotely. &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-79411","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/79411","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=79411"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/79411\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=79411"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=79411"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=79411"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}