Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 08 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 06 Jun 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gl-inet mt3000
|
|
| Vendors & Products |
Gl-inet mt3000
|
Sat, 06 Jun 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was determined in GL.iNet MT3000 up to 4.4.5. This vulnerability affects unknown code of the file ovpnclient.sh of the component OpenVPN Client Import Workflow. This manipulation causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 4.9.0_beta3-1012-0513-1778656146 is able to resolve this issue. You should upgrade the affected component. The vendor confirms: "This issue has been addressed by implementing malicious checks on OpenVPN configuration files to prevent command injection attacks carried through malicious configuration files." | |
| Title | GL.iNet MT3000 OpenVPN Client Import Workflow ovpnclient.sh command injection | |
| First Time appeared |
Gl-inet
Gl-inet mt3000 Firmware |
|
| Weaknesses | CWE-74 CWE-77 |
|
| CPEs | cpe:2.3:o:gl-inet:mt3000_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gl-inet
Gl-inet mt3000 Firmware |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-08T16:27:56.919Z
Reserved: 2026-06-05T18:26:22.054Z
Link: CVE-2026-11406
Updated: 2026-06-08T16:27:28.137Z
Status : Deferred
Published: 2026-06-06T10:16:27.017
Modified: 2026-06-08T14:57:14.757
Link: CVE-2026-11406
No data.
OpenCVE Enrichment
Updated: 2026-06-06T11:30:19Z