CVE-2025-67089: Gl-Inet Gl-AXT1800 Firmware

High severity, CVSS 8.1. EPSS: 1.6% chance of exploitation in the next 30 days.

A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_package` RPC method, which fails to properly sanitize user input in package names. Authenticated attackers can exploit this to execute arbitrary commands with root privileges

Affected products

  • Gl-Inet Gl-AXT1800 Firmware: version 4.2.0 only; version 4.6.4 only; version 4.6.8 only

Published 2026-01-08. Last modified 2026-06-17.