A vulnerability classified as critical has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/plugins.install_package of the file /cgi-bin/glc of the component plugins.so Native Plugin. This manipulation causes command injection.

This vulnerability is handled as CVE-2026-18612. The attack can be initiated remotely. Additionally, an exploit exists.

The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.