Gl-mt3000
This hub aggregates every CVE we track for Gl-mt3000, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
17
CVEs tracked
3
Critical
10
High
0
In CISA KEV
Severity distribution
HIGH10MEDIUM4CRITICAL3
Monthly trend
1
0
2
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
1
9
0
2024-082026-07
Latest CVEs
The 15 most recently published vulnerabilities affecting Gl-mt3000.
- CVE-2026-12187GL.iNet GL-MT3000 Online Firmware Upgrade one_click_upgrade command injection8.8
- CVE-2026-12186GL.iNet GL-MT3000 Tor Proxy Service Configuration tor replace_country command injection8.8
- CVE-2026-11452GL.iNet GL-MT3000 SET_USER_PWD glc FUN_0042e200 command injection7.3
- CVE-2026-11451GL.iNet GL-MT3000 FTP Protocol glc snprintf command injection7.3
- CVE-2026-11450GL.iNet GL-MT3000 Path Normalization dlopen command injection7.3
- CVE-2026-11449GL.iNet GL-MT3000 LuCI JSON-RPC rpc rpc_sys command injection6.3
- CVE-2026-11448GL.iNet GL-MT3000 Minidlna Service rpc realpath command injection4.7
- CVE-2026-11447GL.iNet GL-MT3000 MTK Backend iwinfo.so iwinfo_backend command injection6.3
- CVE-2026-11406GL.iNet MT3000 OpenVPN Client Import Workflow ovpnclient.sh command injection6.3
- CVE-2023-46453Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username that is both a valid SQL statement and a valid regular expre...9.8
- CVE-2025-25685An issue was discovered in GL-INet Beryl AX GL-MT3000 v4.7.0. Attackers are able to download arbitrary files from the device's file system via adding symbolic links on an external drive used as a s...7.5
- CVE-2024-45260An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized groups can invoke any interface of the device, ther...8.0
- CVE-2024-45261An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not tied to that user itself, which allows ...8.0
- CVE-2024-39226GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and X...9.8
- CVE-2024-27356An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user information. This affects MT6000 4.5.5, XE3000 4.4.4,...7.5
Product normalization is registry-driven with AI assist and human review. How it works