GHSA-jrxr-jp3v-2pw6MediumCVSS 4.3
A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500,...
🔗 CVE IDs covered (1)
📋 Description
A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. The affected element is the function nas-web.get_file_list of the component APPS-NAS Module. Performing a manipulation results in heap-based buffer overflow. The attack may be initiated remotely. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2026-18585
- https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Heap%20buffer%20overflow%20in%20nas-web.get_file_list%20leading%20to%20authenticated%20denial%20of%20service.md
- https://vuldb.com/cve/CVE-2026-18585
- https://vuldb.com/submit/849290
- https://vuldb.com/vuln/385414
- https://vuldb.com/vuln/385414/cti
- https://github.com/advisories/GHSA-jrxr-jp3v-2pw6