๐Ÿ” CVE Alert

CVE-2026-11406

MEDIUM 6.3

GL.iNet MT3000 OpenVPN Client Import Workflow ovpnclient.sh command injection

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was determined in GL.iNet MT3000 up to 4.4.5. This vulnerability affects unknown code of the file ovpnclient.sh of the component OpenVPN Client Import Workflow. This manipulation causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 4.9.0_beta3-1012-0513-1778656146 is able to resolve this issue. You should upgrade the affected component. The vendor confirms: "This issue has been addressed by implementing malicious checks on OpenVPN configuration files to prevent command injection attacks carried through malicious configuration files."

CWE CWE-77 CWE-74
Vendor gl.inet
Product mt3000
Published Jun 6, 2026
Last Updated Jun 8, 2026
Stay Ahead of the Next One

Get instant alerts for gl.inet mt3000

Be the first to know when new medium vulnerabilities affecting gl.inet mt3000 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

GL.iNet / MT3000
4.4.0 4.4.1 4.4.2 4.4.3 4.4.4 4.4.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/368966 vuldb.com: https://vuldb.com/vuln/368966/cti vuldb.com: https://vuldb.com/cve/CVE-2026-11406 vuldb.com: https://vuldb.com/submit/820049 github.com: https://github.com/StrTzz123/iot_vul/tree/main/GL-iNet/MT3000/4.4.5/ovpn_client_import fw.gl-inet.cn: https://fw.gl-inet.cn/firmware/mt3000/testing/mt3000-4.9.0_beta3-1012-0513-1778656146.tar

Credits

๐Ÿ” strforexc (VulDB User) VulDB CNA Team