CVE-2026-18585 PUBLISHED

GL.iNet MT2500 APPS-NAS nas-web.get_file_list heap-based overflow

Assigner: VulDB
Reserved: 02.08.2026 Published: 03.08.2026 Updated: 03.08.2026

A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. The affected element is the function nas-web.get_file_list of the component APPS-NAS Module. Performing a manipulation results in heap-based buffer overflow. The attack may be initiated remotely. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X
CVSS Score: 5.3

Product Status

Vendor GL.iNet
Product MT3000
Versions
  • Version 20260707 is affected
Vendor GL.iNet
Product MT6000
Versions
  • Version 20260707 is affected
Vendor GL.iNet
Product BE9300
Versions
  • Version 20260707 is affected
Vendor GL.iNet
Product BE3600
Versions
  • Version 20260707 is affected
Vendor GL.iNet
Product MT3600BE
Versions
  • Version 20260707 is affected
Vendor GL.iNet
Product E5800
Versions
  • Version 20260707 is affected
Vendor GL.iNet
Product BE6500
Versions
  • Version 20260707 is affected
Vendor GL.iNet
Product MT5000
Versions
  • Version 20260707 is affected
Vendor GL.iNet
Product X3000
Versions
  • Version 20260707 is affected
Vendor GL.iNet
Product XE3000
Versions
  • Version 20260707 is affected
Vendor GL.iNet
Product MT2500
Versions
  • Version 20260707 is affected

Credits

  • GLiNet (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Heap-based Buffer Overflow CWE
  • Memory Corruption CWE