CVE-2026-12186

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function replace_country in the library /usr/lib/oui-httpd/rpc/tor of the component Tor Proxy Service Configuration Handler. This manipulation causes command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 4.7 is able to address this issue. It is recommended to upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Configurations

No configuration.

History

23 Jul 2026, 11:10

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una debilidad en GL.iNet GL-MT3000 hasta la versión 4.4.5. Afecta a la función replace_country en la biblioteca /usr/lib/oui-httpd/rpc/tor del componente Gestor de Configuración del Servicio de Proxy Tor. Esta manipulación provoca inyección de comandos. El ataque puede iniciarse de forma remota. El exploit se ha hecho público y podría utilizarse para ataques. La actualización a la versión 4.7 es capaz de solucionar este problema. Se recomienda actualizar el componente afectado. Se contactó al proveedor con antelación, respondió de manera muy profesional y lanzó rápidamente una versión corregida del producto afectado.

14 Jun 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-14 21:16

Updated : 2026-07-24 12:10


NVD link : CVE-2026-12186

Mitre link : CVE-2026-12186

CVE.ORG link : CVE-2026-12186


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')