CVE-2026-11448 PUBLISHED

GL.iNet GL-MT3000 Minidlna Service rpc realpath command injection

Assigner: VulDB
Reserved: 06.06.2026 Published: 07.06.2026 Updated: 07.06.2026

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function realpath of the file /rpc of the component Minidlna Service. This manipulation of the argument kube. set causes command injection. The attack is possible to be carried out remotely. Upgrading to version 4.7 is sufficient to fix this issue. It is recommended to upgrade the affected component. The vendor confirms: "Starting from version 4.7, SDK has added global protection to intercept malicious injection".

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
CVSS Score: 5.1

Product Status

Vendor GL.iNet
Product GL-MT3000
Versions
  • Version 4.4.0 is affected
  • Version 4.4.1 is affected
  • Version 4.4.2 is affected
  • Version 4.4.3 is affected
  • Version 4.4.4 is affected
  • Version 4.4.5 is affected
  • Version 4.7 is unaffected

Credits

  • strforexc (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Command Injection CWE
  • Injection CWE