« Volver al listado

CVE-2026-18585

Estado: AplazadaMedia (5.3)—

A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. The affected element is the function nas-web.get_file_list of the component APPS-NAS Module. Performing a manipulation results in heap-based buffer overflow. The attack may be initiated remotely. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (11)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-18585",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-18585",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-08-03T13:20:50.996638Z"
        }
      }
    ],
    "cvssMetricV2": [
      {
        "type": "Secondary",
        "source": "cna@vuldb.com",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cna@vuldb.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "cna@vuldb.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 5.3,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "LOW",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "LOW",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "cna@vuldb.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:gl.inet:mt3000:*:*:*:*:*:*:*:*"
          ],
          "vendor": "GL.iNet",
          "modules": [
            "APPS-NAS Module"
          ],
          "product": "MT3000",
          "versions": [
            {
              "status": "affected",
              "version": "20260707"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:gl.inet:mt6000:*:*:*:*:*:*:*:*"
          ],
          "vendor": "GL.iNet",
          "modules": [
            "APPS-NAS Module"
          ],
          "product": "MT6000",
          "versions": [
            {
              "status": "affected",
              "version": "20260707"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:gl.inet:be9300:*:*:*:*:*:*:*:*"
          ],
          "vendor": "GL.iNet",
          "modules": [
            "APPS-NAS Module"
          ],
          "product": "BE9300",
          "versions": [
            {
              "status": "affected",
              "version": "20260707"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:gl.inet:be3600:*:*:*:*:*:*:*:*"
          ],
          "vendor": "GL.iNet",
          "modules": [
            "APPS-NAS Module"
          ],
          "product": "BE3600",
          "versions": [
            {
              "status": "affected",
              "version": "20260707"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:gl.inet:mt3600be:*:*:*:*:*:*:*:*"
          ],
          "vendor": "GL.iNet",
          "modules": [
            "APPS-NAS Module"
          ],
          "product": "MT3600BE",
          "versions": [
            {
              "status": "affected",
              "version": "20260707"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:gl.inet:e5800:*:*:*:*:*:*:*:*"
          ],
          "vendor": "GL.iNet",
          "modules": [
            "APPS-NAS Module"
          ],
          "product": "E5800",
          "versions": [
            {
              "status": "affected",
              "version": "20260707"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:gl.inet:be6500:*:*:*:*:*:*:*:*"
          ],
          "vendor": "GL.iNet",
          "modules": [
            "APPS-NAS Module"
          ],
          "product": "BE6500",
          "versions": [
            {
              "status": "affected",
              "version": "20260707"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:gl.inet:mt5000:*:*:*:*:*:*:*:*"
          ],
          "vendor": "GL.iNet",
          "modules": [
            "APPS-NAS Module"
          ],
          "product": "MT5000",
          "versions": [
            {
              "status": "affected",
              "version": "20260707"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:gl.inet:x3000:*:*:*:*:*:*:*:*"
          ],
          "vendor": "GL.iNet",
          "modules": [
            "APPS-NAS Module"
          ],
          "product": "X3000",
          "versions": [
            {
              "status": "affected",
              "version": "20260707"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:gl.inet:xe3000:*:*:*:*:*:*:*:*"
          ],
          "vendor": "GL.iNet",
          "modules": [
            "APPS-NAS Module"
          ],
          "product": "XE3000",
          "versions": [
            {
              "status": "affected",
              "version": "20260707"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:gl.inet:mt2500:*:*:*:*:*:*:*:*"
          ],
          "vendor": "GL.iNet",
          "modules": [
            "APPS-NAS Module"
          ],
          "product": "MT2500",
          "versions": [
            {
              "status": "affected",
              "version": "20260707"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-08-03T06:16:37.710",
  "references": [
    {
      "url": "https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/Heap%20buffer%20overflow%20in%20nas-web.get_file_list%20leading%20to%20authenticated%20denial%20of%20service.md",
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://vuldb.com/cve/CVE-2026-18585",
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://vuldb.com/submit/849290",
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://vuldb.com/vuln/385414",
      "source": "cna@vuldb.com"
    },
    {
      "url": "https://vuldb.com/vuln/385414/cti",
      "source": "cna@vuldb.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cna@vuldb.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        },
        {
          "lang": "en",
          "value": "CWE-122"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. The affected element is the function nas-web.get_file_list of the component APPS-NAS Module. Performing a manipulation results in heap-based buffer overflow. The attack may be initiated remotely. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability."
    }
  ],
  "lastModified": "2026-08-12T21:00:37.147",
  "sourceIdentifier": "cna@vuldb.com"
}