CVE Tools

Gl-inet

40 CVEs tracked since 2022. Since Oct 2022, none of them reached CISA KEV.

Gl-inet CVEs per month

Oct 2022 to Mar 2026. Point at a month, or focus the strip and use the arrow keys.
Gl-inet CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2022-1030
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-0590
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-1240
2024-0140
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-0860
2024-09null or fewer
2024-1050
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-0390

Products

The products that kept showing up in Gl-inet's monthly top three, with their CVEs summed over those months.

  1. AR300M16 Firmware163 months
  2. A1300 Firmware112 months
  3. Gl-ar300m Firmware82 months
  4. Gl-mt3000 Firmware81 month
  5. Gl-mv1000 Firmware81 month
  6. Gl-mv1000w Firmware81 month
  7. XE300 Firmware61 month
  8. AR300M Firmware51 month
  9. Comet Gl-rm1 Firmware41 month
  10. Comet Kvm41 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Gl-inet.

  1. CVE-2026-18616GL-iNet GL-MT3000 wg-server.so Native Plugin glc server.set_peer command injection9.8
  2. CVE-2026-18615GL-iNet GL-MT3000 wg-server.so Native Plugin glc wg-server.generate_publickey command injection9.8
  3. CVE-2026-18614GL-iNet GL-MT3000 s2s.so Native Plugin glc s2s.enable_echo_server command injection9.8
  4. CVE-2026-18613GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection9.8
  5. CVE-2026-18612GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.install_package command injection9.8
  6. CVE-2026-32293GL-iNet Comet (GL-RM1) KVM insufficient certificate validation3.7
  7. CVE-2026-32292GL-iNet Comet (GL-RM1) KVM insufficient login rate-limiting7.5
  8. CVE-2026-32291GL-iNet Comet (GL-RM1) KVM unauthenticated root access via UART serial console6.8
  9. CVE-2026-32290GL-iNet Comet (GL-RM1) KVM insufficient firmware verification4.7
  10. CVE-2026-26792GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, target_version, current_version, firmware_upload, has...9.8
  11. CVE-2026-26795GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. This vulnerability allows attackers to execute arb...9.8
  12. CVE-2026-26794GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This vulnerability allows attackers to execute arbitrary SQL database operations vi...8.8
  13. CVE-2026-26793GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. This vulnerability allows attackers to execute arbitrary commands via a crafted ...9.8
  14. CVE-2026-26791GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server function. This vulnerability allows attackers to exec...9.8
  15. CVE-2025-67090The LuCI web interface on Gl Inet GL.Inet AX1800 Version 4.6.4 & 4.6.8 are vulnerable. Fix available in version 4.8.2 GL.Inet AX1800 Version 4.6.4 & 4.6.8 lacks rate limiting or account lockout mec...5.1

The record

Peak rank
#80 in May 2023
Busiest month shown
May 2023, 9 CVEs
Months with a KEV entry
0 since Oct 2022
Monthly snapshots
7 since 2022
Gl-inet's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store