CVE-2025-67089

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
08/01/2026
Last modified:
16/01/2026

Description

A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_package` RPC method, which fails to properly sanitize user input in package names. Authenticated attackers can exploit this to execute arbitrary commands with root privileges

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:gl-inet:gl-axt1800_firmware:4.2.0:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-axt1800_firmware:4.6.4:*:*:*:*:*:*:*
cpe:2.3:o:gl-inet:gl-axt1800_firmware:4.6.8:*:*:*:*:*:*:*
cpe:2.3:h:gl-inet:gl-axt1800:-:*:*:*:*:*:*:*