gl-inet
Latest CVEs
The 15 most recently published vulnerabilities affecting gl-inet.
- CVE-2026-18616GL-iNet GL-MT3000 wg-server.so Native Plugin glc server.set_peer command injection9.8
- CVE-2026-18615GL-iNet GL-MT3000 wg-server.so Native Plugin glc wg-server.generate_publickey command injection9.8
- CVE-2026-18614GL-iNet GL-MT3000 s2s.so Native Plugin glc s2s.enable_echo_server command injection9.8
- CVE-2026-18613GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection9.8
- CVE-2026-18612GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.install_package command injection9.8
- CVE-2026-32293GL-iNet Comet (GL-RM1) KVM insufficient certificate validation3.7
- CVE-2026-32292GL-iNet Comet (GL-RM1) KVM insufficient login rate-limiting7.5
- CVE-2026-32291GL-iNet Comet (GL-RM1) KVM unauthenticated root access via UART serial console6.8
- CVE-2026-32290GL-iNet Comet (GL-RM1) KVM insufficient firmware verification4.7
- CVE-2026-26792GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, target_version, current_version, firmware_upload, has...9.8
- CVE-2026-26795GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. This vulnerability allows attackers to execute arb...9.8
- CVE-2026-26791GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server function. This vulnerability allows attackers to exec...9.8
- CVE-2026-26794GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This vulnerability allows attackers to execute arbitrary SQL database operations vi...8.8
- CVE-2026-26793GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. This vulnerability allows attackers to execute arbitrary commands via a crafted ...9.8
- CVE-2025-67090The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL.Inet AX1800 Version 4.6.4 & 4.6.8 lacks rate limiting or account lockout mec...5.1