No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 07 Jun 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function realpath of the file /rpc of the component Minidlna Service. This manipulation of the argument kube. set causes command injection. The attack is possible to be carried out remotely. Upgrading to version 4.7 is sufficient to fix this issue. It is recommended to upgrade the affected component. The vendor confirms: "Starting from version 4.7, SDK has added global protection to intercept malicious injection". | |
| Title | GL.iNet GL-MT3000 Minidlna Service rpc realpath command injection | |
| First Time appeared |
Gl-inet
Gl-inet gl-mt3000 Firmware |
|
| Weaknesses | CWE-74 CWE-77 |
|
| CPEs | cpe:2.3:o:gl-inet:gl-mt3000_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gl-inet
Gl-inet gl-mt3000 Firmware |
|
| References |
| |
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-07T02:00:13.687Z
Reserved: 2026-06-06T10:33:12.835Z
Link: CVE-2026-11448
No data.
Status : Received
Published: 2026-06-07T03:16:26.233
Modified: 2026-06-07T03:16:26.233
Link: CVE-2026-11448
No data.
OpenCVE Enrichment
Updated: 2026-06-07T03:30:35Z