CVE-2025-67089
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
08/01/2026
Last modified:
08/01/2026
Description
A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_package` RPC method, which fails to properly sanitize user input in package names. Authenticated attackers can exploit this to execute arbitrary commands with root privileges
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH



