peter bassill · operator
$ cve CVE-2026-18686 JSON

CVE-2026-18686

9.8
CRITICAL · CVSS 3.1 · EPSS 4.7% (pctl 92)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.73% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-74
On CISA KEVno
Public exploitnone known
Published2026-08-04
Last modified2026-08-12

References

→ the Explorer  ·  watch your stack  ·  NVD