A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5 and classified as critical. The impacted element is the function
server.set_peer of the file /cgi-bin/glc of the component wg-server.so Native Plugin. The manipulation of the argument public_key leads to command injection.
This vulnerability is referenced as CVE-2026-18616. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.