๐Ÿ” CVE Alert

CVE-2026-18585

MEDIUM 4.3

GL.iNet MT2500 APPS-NAS nas-web.get_file_list heap-based overflow

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. The affected element is the function nas-web.get_file_list of the component APPS-NAS Module. Performing a manipulation results in heap-based buffer overflow. The attack may be initiated remotely. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

CWE CWE-122 CWE-119
Vendor gl.inet
Product mt3000
Published Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for gl.inet mt3000

Be the first to know when new medium vulnerabilities affecting gl.inet mt3000 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:X/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

GL.iNet / MT3000
20260707
GL.iNet / MT6000
20260707
GL.iNet / BE9300
20260707
GL.iNet / BE3600
20260707
GL.iNet / MT3600BE
20260707
GL.iNet / E5800
20260707
GL.iNet / BE6500
20260707
GL.iNet / MT5000
20260707
GL.iNet / X3000
20260707
GL.iNet / XE3000
20260707
GL.iNet / MT2500
20260707

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/385414 vuldb.com: https://vuldb.com/vuln/385414/cti vuldb.com: https://vuldb.com/cve/CVE-2026-18585 vuldb.com: https://vuldb.com/submit/849290 github.com: https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Heap%20buffer%20overflow%20in%20nas-web.get_file_list%20leading%20to%20authenticated%20denial%20of%20service.md

Credits

๐Ÿ” GLiNet (VulDB User) VulDB CNA Team