CVE-2026-12187
GL.iNet GL-MT3000 Online Firmware Upgrade one_click_upgrade command injection
Vexday Risk Score
41Atención
Decisión SSVC (CISA)
Attend
PoC disponible → seguir de cerca
CVSS 8.7EPSS 1.9%KEV nãoPoC públicaNuclei —Metasploit —Patch referenciado
Ciclo de vida
14 jun 2026Publicada en NVD
Recomendación: Planificar corrección próxima — ya existe PoC pública.
A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Affected by this vulnerability is an unknown functionality of the file /usr/bin/one_click_upgrade of the component Online Firmware Upgrade Handler. Such manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 4.7 addresses this issue. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Productos afectados
GL.iNet · GL-MT3000PoCs públicas encontradas — 1
cve_referencegithub.com/StrTzz123/iot_vul/tree/main/GL-iNet/MT3000/4.4.5/upgrade_online_urlno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://fw.gl-inet.com/firmware/mt3000/release/mt3000-4.8.1-0819-1755615825.tarhttps://github.com/StrTzz123/iot_vul/tree/main/GL-iNet/MT3000/4.4.5/upgrade_online_urlhttps://vuldb.com/cve/CVE-2026-12187https://vuldb.com/submit/815654https://vuldb.com/vuln/370833https://vuldb.com/vuln/370833/cti