CVE-2026-18585

Summary

A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. The affected element is the function nas-web.get_file_list of the component APPS-NAS Module. Performing a manipulation results in heap-based buffer overflow. The attack may be initiated remotely. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

Affected Software

VendorProductVersion RangeStatus
GL.iNetMT300020260707affected
GL.iNetMT600020260707affected
GL.iNetBE930020260707affected
GL.iNetBE360020260707affected
GL.iNetMT3600BE20260707affected
GL.iNetE580020260707affected
GL.iNetBE650020260707affected
GL.iNetMT500020260707affected
GL.iNetX300020260707affected
GL.iNetXE300020260707affected
GL.iNetMT250020260707affected

Weaknesses

  • CWE-122: Heap-based Buffer Overflow
  • CWE-119: Memory Corruption

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References