VYPR

GL-AR300M16

by Gl Inet

CVEs (5)

  • CVE-2026-26791Mar 12, 2026
    risk 0.00cvss epss 0.01

    GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.

  • CVE-2026-26793Mar 12, 2026
    risk 0.00cvss epss 0.01

    GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.

  • CVE-2026-26795Mar 12, 2026
    risk 0.00cvss epss 0.01

    GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. This vulnerability allows attackers to execute arbitrary commands via a crafted input.

  • CVE-2026-26794Mar 12, 2026
    risk 0.00cvss epss 0.00

    GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This vulnerability allows attackers to execute arbitrary SQL database operations via a crafted HTTP request.

  • CVE-2026-26792Mar 12, 2026
    risk 0.00cvss epss 0.01

    GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, target_version, current_version, firmware_upload, hash_type, hash_value, and upgrade_type parameters. These vulnerabilities allow attackers to execute arbitrary commands via a crafted input.