A vulnerability has been found in GL-iNet GL-AR300M16 4.3.11 and classified as critical. Affected is the function
M.get_system_log. Performing a manipulation of the argument module results in command injection.
This vulnerability is known as CVE-2026-26795. Remote exploitation of the attack is possible. No exploit is available.