A vulnerability classified as critical was found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the component plugins.so Native Plugin. Such manipulation leads to injection.

This vulnerability is uniquely identified as CVE-2026-18613. The attack can be launched remotely. Moreover, an exploit is present.

The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.