CVE-2026-11450 is a remote command injection vulnerability affecting GL.iNet GL-MT3000 firmware version 4.4.5. The issue is in the Path Normalization Handler associated with the /usr/lib/oui-httpd/rpc/ component, specifically involving the dlopen-related code path. By manipulating the dev_name argument, an attacker can inject operating system commands. The vendor states that the reported exploit chain reached the dangerous functionality via the HTTP /rpc layer and the nas-web.eject_disk method, indicating insufficient validation and exposure of a sensitive RPC method in the vulnerable version.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a small standalone Python proof-of-concept exploit and a README. The exploit targets three unauthenticated command injection vulnerabilities in GL.iNet GL-MT3000 (Beryl AX) firmware <= 4.4.5, all reachable through the /cgi-bin/glc web CGI dispatcher. The script is not part of a larger exploitation framework. Structure: README.md documents the CVEs, affected versions, usage examples, and prerequisites. poc.py is the sole executable component and serves as the entry point. It uses Python standard-library modules only (json, ssl, urllib, argparse, time, shlex). Core behavior: poc.py builds JSON POST requests to /cgi-bin/glc with object set to nas-web and varying method names. It disables TLS certificate validation, allowing exploitation over HTTPS against devices with self-signed certs. The helper glc_call() centralizes request construction and response handling. Exploit capabilities by CVE: CVE-2026-11450 abuses the eject_disk_do1 method by crafting a long dev_name value that appends a shell command substitution payload $(cmd>outfile), relying on a buffer-length mismatch between an access() check and a later system() call. CVE-2026-11451 abuses set_proto_config by injecting shell metacharacters into the FTP media_dir parameter using a single-quote break-out sequence (/x';cmd>outfile 2>&1;#). CVE-2026-11452 abuses set_user_pwd by first enabling/starting NAS services, enumerating existing NAS users with get_user_list, then injecting a command substitution payload into the password field for a selected user. Operational result: successful exploitation yields arbitrary command execution on the router, with output redirected to files on the target filesystem for manual verification. The script supports running one CVE or all three in sequence. Because it includes working payloads and execution logic but no advanced operator tooling, it is best classified as an operational PoC rather than a detection script or weaponized framework module.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.