Metrics
Affected Vendors & Products
Sat, 06 Jun 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gl-inet mt3000
|
|
| Vendors & Products |
Gl-inet mt3000
|
Sat, 06 Jun 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in GL.iNet MT3000 up to 4.4.5. This vulnerability affects unknown code of the file ovpnclient.sh of the component OpenVPN Client Import Workflow. This manipulation causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 4.9.0_beta3-1012-0513-1778656146 is able to resolve this issue. You should upgrade the affected component. The vendor confirms: "This issue has been addressed by implementing malicious checks on OpenVPN configuration files to prevent command injection attacks carried through malicious configuration files." | |
| Title | GL.iNet MT3000 OpenVPN Client Import Workflow ovpnclient.sh command injection | |
| First Time appeared |
Gl-inet
Gl-inet mt3000 Firmware |
|
| Weaknesses | CWE-74 CWE-77 |
|
| CPEs | cpe:2.3:o:gl-inet:mt3000_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gl-inet
Gl-inet mt3000 Firmware |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-06T09:15:12.019Z
Reserved: 2026-06-05T18:26:22.054Z
Link: CVE-2026-11406
No data.
Status : Received
Published: 2026-06-06T10:16:27.017
Modified: 2026-06-06T10:16:27.017
Link: CVE-2026-11406
No data.
OpenCVE Enrichment
Updated: 2026-06-06T11:30:19Z