CVE-2026-18585

MEDIUM CVSS 4.0: 5.3 EPSS 0.30%
Updated Aug 13, 2026
Gl.Inet
Parameter Value
CVSS 5.3 (MEDIUM)
Type CWE-119 (Buffer Overflow), CWE-122 (Heap-based Buffer Overflow)
Vendor Gl.Inet
Public PoC No

A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. The affected element is the function nas-web.get_file_list of the component APPS-NAS Module. Performing a manipulation results in heap-based buffer overflow.

The attack may be initiated remotely. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
Low
Partial disruption

CVSS Vector v4.0

Vulnerable Products

gl.inet:mt6000 gl.inet:e5800 gl.inet:be3600 gl.inet:be9300 gl.inet:be6500 gl.inet:mt5000 gl.inet:mt2500 gl.inet:mt3000 gl.inet:xe3000 gl.inet:x3000 gl.inet:mt3600be