CVE-2023-29778: Gl-Inet Gl-MT3000 Firmware

Critical severity, CVSS 9.8. EPSS: 16% chance of exploitation in the next 30 days.

GL.iNET MT3000 4.1.0 Release 2 is vulnerable to OS Command Injection via /usr/lib/oui-httpd/rpc/logread.

Affected products

  • Gl-Inet Gl-MT3000 Firmware: version 4.1.0 only

Published 2023-05-02. Last modified 2026-07-09.