A vulnerability described as critical has been identified in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function
ovpn-client.get_recommend_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Executing a manipulation of the argument Hostname can lead to command injection.
This vulnerability is handled as CVE-2026-18602. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.