Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · gl-inet

gl-inet

· 17 Critical

Total CVEs

57

Critical

17

Products

135

Search All CVEs →

57

Products (135)

gl-mt300018 CVEsar300m16 firmware17 CVEsar300m1617 CVEsgl-ax180016 CVEsgl-ax1800 firmware16 CVEsgl-ar300m firmware15 CVEsgl-ar300m15 CVEsax180014 CVEsgl-ar750s firmware14 CVEsgl-ar750s14 CVEsax1800 firmware14 CVEsgl-mt3000 firmware13 CVEsgl-axt1800 firmware13 CVEsgl-axt180013 CVEsgl-mt300n-v2 firmware13 CVEsgl-mt300n-v213 CVEsa130012 CVEsa1300 firmware12 CVEsar300m12 CVEsar300m firmware12 CVEsar75012 CVEsar750 firmware12 CVEsar750s12 CVEsar750s firmware12 CVEsaxt180012 CVEsaxt1800 firmware12 CVEsb130012 CVEsb1300 firmware12 CVEsgl-a130012 CVEsgl-a1300 firmware12 CVEsgl-ar75012 CVEsgl-ar750 firmware12 CVEsgl-b130012 CVEsgl-b1300 firmware12 CVEsgl-mt130012 CVEsgl-mt1300 firmware12 CVEsgl-mt250012 CVEsgl-mt2500 firmware12 CVEsmt130012 CVEsmt1300 firmware12 CVEsmt250012 CVEsmt2500 firmware12 CVEsmt3000 firmware12 CVEsmt300n-v212 CVEsmt300n-v2 firmware12 CVEsmt600012 CVEsmt6000 firmware12 CVEssft120012 CVEssft1200 firmware12 CVEsx300012 CVEsx3000 firmware12 CVEsx75012 CVEsx750 firmware12 CVEsxe30012 CVEsxe300012 CVEsxe3000 firmware12 CVEsxe300 firmware12 CVEsx300b firmware11 CVEsx300b11 CVEse750 firmware10 CVEse75010 CVEsgl-e7508 CVEsgl-mv1000 firmware8 CVEsgl-mv10008 CVEsgl-mv1000w8 CVEsgl-mv1000w firmware8 CVEsgl-e750 firmware8 CVEsgl-s2007 CVEsgl-mt2500a7 CVEsgl-mt2500a firmware7 CVEsgl-s107 CVEsgl-s10 firmware7 CVEsgl-s13007 CVEsgl-s1300 firmware7 CVEsgl-s207 CVEsgl-s200 firmware7 CVEsgl-s20 firmware7 CVEsgl-sf12007 CVEsgl-sf1200 firmware7 CVEsgl-sft12007 CVEsgl-sft1200 firmware7 CVEsgl-usb1507 CVEsgl-usb150 firmware7 CVEsgl-x12007 CVEsgl-x1200 firmware7 CVEsgl-x30007 CVEsgl-x3000 firmware7 CVEsgl-x300b7 CVEsgl-x300b firmware7 CVEsgl-x7507 CVEsgl-x750 firmware7 CVEsgl-xe3007 CVEsgl-xe300 firmware7 CVEsmicrouter-n3007 CVEsmicrouter-n300 firmware7 CVEsmt30007 CVEsgl-ap1300lte7 CVEsgl-ap1300lte firmware7 CVEsgl-ap1300 firmware7 CVEsgl-ap13007 CVEsgl-b22007 CVEsgl-b2200 firmware7 CVEsgl-mifi7 CVEsgl-mifi firmware7 CVEss13006 CVEss1300 firmware6 CVEssf1200 firmware6 CVEssf12006 CVEsmv10006 CVEsn300 firmware6 CVEsb22006 CVEsn3006 CVEsmv1000 firmware6 CVEsb2200 firmware6 CVEsusb1505 CVEsmv1000w5 CVEsap13005 CVEsap1300 firmware5 CVEsb3000 firmware5 CVEsb30005 CVEsmv1000w firmware5 CVEsgl-mt6000 firmware5 CVEsgl-mt60005 CVEsusb150 firmware5 CVEsgl-ar300m-lite4 CVEsgoodcloud4 CVEscomet gl-rm1 firmware4 CVEscomet gl-rm14 CVEsgl-ar300m-lite firmware4 CVEss2001 CVEsx1200 firmware1 CVEsgl-ar150 firmware1 CVEsx12001 CVEsgl-ar1501 CVEss200 firmware1 CVEs

Recent Vulnerabilities

View all 57
CVE-2026-32293LOW 3.7

The GL-iNet Comet (GL-RM1) KVM connects to a GL-iNet site during boot-up to provision client and CA certificates. The GL-RM1 does not verify certificates used for this connection, allowing an attacker-in-the-middle to serve invalid client and CA certificates. The GL-RM1 will attempt to use the invalid certificates and fail to connect to the legitimate GL-iNet KVM cloud service.

CVE-2026-32292HIGH 7.5

The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess credentials.

CVE-2026-32291MEDIUM 6.8

The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requires physically opening the device and connecting to the UART pins.

CVE-2026-32290MEDIUM 4.7

The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 does not sufficiently verify the authenticity of uploaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the corresponding MD5 hash to pass verification.

CVE-2026-26793CRITICAL 9.8

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.

CVE-2026-26795CRITICAL 9.8

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.

CVE-2026-26794HIGH 8.8

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This vulnerability allows attackers to execute arbitrary SQL database operations via a crafted HTTP request.

CVE-2026-26792CRITICAL 9.8

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, target_version, current_version, firmware_upload, hash_type, hash_value, and upgrade_type parameters. These vulnerabilities allow attackers to execute arbitrary commands via a crafted input.

CVE-2026-26791CRITICAL 9.8

GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.

CVE-2025-67091MEDIUM 6.5

An issue in GL Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. GL.Inet AX1800 Version 4.6.4 & 4.6.8 in the GL.iNet custom opkg wrapper script located at /usr/libexec/opkg-call. The script is executed with root privileges when triggered via the LuCI web interface or authenticated API calls to manage packages. The vulnerable code uses shell redirection to create a lock file in the world-writable /tmp directory.

CVE-2025-67090MEDIUM 5.1

The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL.Inet AX1800 Version 4.6.4 & 4.6.8 lacks rate limiting or account lockout mechanisms on the authentication endpoint (`/cgi-bin/luci`). An unauthenticated attacker on the local network can perform unlimited password attempts against the admin interface.

CVE-2025-67089HIGH 8.1

A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_package` RPC method, which fails to properly sanitize user input in package names. Authenticated attackers can exploit this to execute arbitrary commands with root privileges

CVE-2024-45263HIGH 8.8

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The upload interface allows the uploading of arbitrary files to the device. Once the device executes the files, it can lead to information leakage, enabling complete control.

CVE-2024-45262HIGH 8.8

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call method of the /rpc endpoint is vulnerable to arbitrary directory traversal, which enables attackers to execute scripts under any path.

CVE-2024-45261HIGH 8.0

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The SID generated for a specific user is not tied to that user itself, which allows other users to potentially use it for authentication. Once an attacker bypasses the application's authentication procedures, they can generate a valid SID, escalate privileges, and gain full control.

CVE-2024-45260HIGH 8.0

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. Users who belong to unauthorized groups can invoke any interface of the device, thereby gaining complete control over it.

CVE-2024-45259MEDIUM 6.5

An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. By intercepting an HTTP request and changing the filename property in the download interface, any file on the device can be deleted.

CVE-2024-28077HIGH 7.5

A denial-of-service issue was discovered on certain GL-iNet devices. Some websites can detect devices exposed to the external network through DDNS, and consequently obtain the IP addresses and ports of devices that are exposed. By using special usernames and special characters (such as half parentheses or square brackets), one can call the login interface and cause the session-management program to crash, resulting in customers being unable to log into their devices. This affects MT6000 4.5.6, XE3000 4.4.5, X3000 4.4.6, MT3000 4.5.0, MT2500 4.5.0, AXT1800 4.5.0, AX1800 4.5.0, A1300 4.5.0, S200 4.1.4-0300, X750 4.3.7, SFT1200 4.3.7, MT1300 4.3.10, AR750 4.3.10, AR750S 4.3.10, AR300M 4.3.10, AR300M16 4.3.10, B1300 4.3.10, MT300N-V2 4.3.10, and XE300 4.3.16.

CVE-2024-39229MEDIUM 5.3

An issue in GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, XE3000/X3000 v4, and B2200/MV1000/MV1000W/USB150/N300/SF1200 v3.216 allows attackers to intercept communications via a man-in-the-middle attack when DDNS clients are reporting data to the server.

CVE-2024-39227CRITICAL 9.8

GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain insecure permissions in the endpoint /cgi-bin/glc. This vulnerability allows unauthenticated attackers to execute arbitrary code or possibly a directory traversal via crafted JSON data.

CVE-2024-39228CRITICAL 9.8

GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a shell injection vulnerability via the interface check_ovpn_client_config and check_config.

CVE-2024-39226CRITICAL 9.8

GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a vulnerability can be exploited to manipulate routers by passing malicious shell commands through the s2s API.

CVE-2024-39225CRITICAL 9.8

GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3000/X3000 v4.4 were discovered to contain a remote code execution (RCE) vulnerability.

CVE-2024-27356HIGH 7.5

An issue was discovered on certain GL-iNet devices. Attackers can download files such as logs via commands, potentially obtaining critical user information. This affects MT6000 4.5.5, XE3000 4.4.4, X3000 4.4.5, MT3000 4.5.0, MT2500 4.5.0, AXT1800 4.5.0, AX1800 4.5.0, A1300 4.5.0, S200 4.1.4-0300, X750 4.3.7, SFT1200 4.3.7, XE300 4.3.7, MT1300 4.3.10, AR750 4.3.10, AR750S 4.3.10, AR300M 4.3.10, AR300M16 4.3.10, B1300 4.3.10, MT300N-v2 4.3.10, X300B 3.217, S1300 3.216, SF1200 3.216, MV1000 3.216, N300 3.216, B2200 3.216, and X1200 3.203.

CVE-2023-50920MEDIUM 5.5

An issue was discovered on GL.iNet devices before version 4.5.0. They assign the same session ID after each user reboot, allowing attackers to share session identifiers between different sessions and bypass authentication or access control measures. Attackers can impersonate legitimate users or perform unauthorized actions. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.