Critical severity9.8NVD Advisory· Published Mar 12, 2026· Updated Jun 17, 2026
CVE-2026-26795
CVE-2026-26795
Description
GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:o:gl-inet:ar300m16_firmware:4.3.11:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: 4.3.11
Patches
Vulnerability mechanics
References
1- github.com/sezangel/IOT-vul/tree/main/GL-iNet/GL-AR300M16/logread--get_system_lognvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.