Critical severity9.8NVD Advisory· Published Mar 12, 2026· Updated Jun 17, 2026
CVE-2026-26793
CVE-2026-26793
Description
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.
Affected products
3- cpe:2.3:o:gl-inet:ar300m16_firmware:4.3.11:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: 4.3.11
Patches
Vulnerability mechanics
References
1- github.com/sezangel/IOT-vul/tree/main/GL-iNet/GL-AR300M16/set_confignvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.