No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 06 Jun 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gl-inet mt3000
|
|
| Vendors & Products |
Gl-inet mt3000
|
Sat, 06 Jun 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in GL.iNet MT3000 up to 4.4.5. This vulnerability affects unknown code of the file ovpnclient.sh of the component OpenVPN Client Import Workflow. This manipulation causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 4.9.0_beta3-1012-0513-1778656146 is able to resolve this issue. You should upgrade the affected component. The vendor confirms: "This issue has been addressed by implementing malicious checks on OpenVPN configuration files to prevent command injection attacks carried through malicious configuration files." | |
| Title | GL.iNet MT3000 OpenVPN Client Import Workflow ovpnclient.sh command injection | |
| First Time appeared |
Gl-inet
Gl-inet mt3000 Firmware |
|
| Weaknesses | CWE-74 CWE-77 |
|
| CPEs | cpe:2.3:o:gl-inet:mt3000_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gl-inet
Gl-inet mt3000 Firmware |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-06T09:15:12.019Z
Reserved: 2026-06-05T18:26:22.054Z
Link: CVE-2026-11406
No data.
Status : Received
Published: 2026-06-06T10:16:27.017
Modified: 2026-06-06T10:16:27.017
Link: CVE-2026-11406
No data.
OpenCVE Enrichment
Updated: 2026-06-06T11:30:19Z