A vulnerability labeled as critical has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.switch_status of the file /usr/lib/oui-httpd/rpc/network of the component Network Lua RPC Plugin. Such manipulation of the argument switch leads to command injection.

This vulnerability is traded as CVE-2026-18600. The attack may be launched remotely. Furthermore, there is an exploit available.

The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.