CVE-2026-11450

A vulnerability was detected in GL.iNet GL-MT3000 4.4.5. This affects the function dlopen in the library /usr/lib/oui-httpd/rpc/ of the component Path Normalization Handler. Performing a manipulation of the argument dev_name results in command injection. It is possible to initiate the attack remotely. Upgrading to version 4.7 mitigates this issue. It is advisable to upgrade the affected component. The vendor confirms: " From version 4.7 onward, we have enabled method‑level validation at the HTTP /rpc layer. nas‑web.eject_disk is no longer in the whitelist of allowed methods. Consequently, directly calling eject_disk through the default /rpc endpoint returns Invalid params, preventing entry into subsequent dangerous functions and blocking the remote exploit chain described in the report."
Configurations

No configuration.

History

23 Jul 2026, 07:10

Type Values Removed Values Added
Summary
  • (es) Se detectó una vulnerabilidad en GL.iNet GL-MT3000 4.4.5. Esto afecta la función dlopen en la biblioteca /usr/lib/oui-httpd/rpc/ del componente Gestor de Normalización de Rutas. Realizar una manipulación del argumento dev_name resulta en inyección de comandos. Es posible iniciar el ataque remotamente. Actualizar a la versión 4.7 mitiga este problema. Es aconsejable actualizar el componente afectado. El proveedor confirma: 'A partir de la versión 4.7, hemos habilitado la validación a nivel de método en la capa HTTP /rpc. nas?web.eject_disk ya no está en la lista blanca de métodos permitidos. En consecuencia, llamar directamente a eject_disk a través del endpoint /rpc predeterminado devuelve 'Invalid params', impidiendo la entrada a funciones peligrosas subsiguientes y bloqueando la cadena de exploit remoto descrita en el informe.'

08 Jun 2026, 16:16

Type Values Removed Values Added
References () https://github.com/StrTzz123/iot_vul/tree/main/GL-iNet/MT3000/4.4.5/nas_eject_disk_do1_glc_rce - () https://github.com/StrTzz123/iot_vul/tree/main/GL-iNet/MT3000/4.4.5/nas_eject_disk_do1_glc_rce -

07 Jun 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-07 03:16

Updated : 2026-07-23 07:10


NVD link : CVE-2026-11450

Mitre link : CVE-2026-11450

CVE.ORG link : CVE-2026-11450


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')