A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function realpath of the file /rpc of the component Minidlna Service. This manipulation of the argument kube. set causes command injection. The attack is possible to be carried out remotely. Upgrading to version 4.7 is sufficient to fix this issue. It is recommended to upgrade the affected component. The vendor confirms: "Starting from version 4.7, SDK has added global protection to intercept malicious injection".
Metrics
Affected Vendors & Products
References
History
Sun, 07 Jun 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function realpath of the file /rpc of the component Minidlna Service. This manipulation of the argument kube. set causes command injection. The attack is possible to be carried out remotely. Upgrading to version 4.7 is sufficient to fix this issue. It is recommended to upgrade the affected component. The vendor confirms: "Starting from version 4.7, SDK has added global protection to intercept malicious injection". | |
| Title | GL.iNet GL-MT3000 Minidlna Service rpc realpath command injection | |
| First Time appeared |
Gl-inet
Gl-inet gl-mt3000 Firmware |
|
| Weaknesses | CWE-74 CWE-77 |
|
| CPEs | cpe:2.3:o:gl-inet:gl-mt3000_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gl-inet
Gl-inet gl-mt3000 Firmware |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-07T02:00:13.687Z
Reserved: 2026-06-06T10:33:12.835Z
Link: CVE-2026-11448
No data.
Status : Received
Published: 2026-06-07T03:16:26.233
Modified: 2026-06-07T03:16:26.233
Link: CVE-2026-11448
No data.
OpenCVE Enrichment
Updated: 2026-06-07T03:30:35Z