Unrated severityNVD Advisory· Published Aug 3, 2026· Updated Aug 3, 2026
GL.iNet MT2500 APPS-NAS nas-web.get_file_list heap-based overflow
CVE-2026-18585
Description
A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. The affected element is the function nas-web.get_file_list of the component APPS-NAS Module. Performing a manipulation results in heap-based buffer overflow. The attack may be initiated remotely. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
5- vuldb.com/cve/CVE-2026-18585mitrethird-party-advisory
- vuldb.com/submit/849290mitrethird-party-advisory
- github.com/gl-inet/CVE-issues/blob/main/4.0.0/Heap%20buffer%20overflow%20in%20nas-web.get_file_list%20leading%20to%20authenticated%20denial%20of%20service.mdmitrerelated
- vuldb.com/vuln/385414mitrevdb-entrytechnical-description
- vuldb.com/vuln/385414/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.