A vulnerability, which was classified as critical, has been found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection.

This vulnerability was named CVE-2026-18614. The attack may be initiated remotely. In addition, an exploit is available.

The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.