Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 03 Aug 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600, MT3600BE, E5800, BE6500, MT5000, X3000, XE3000 and MT2500 up to 20260707. The affected element is the function nas-web.get_file_list of the component APPS-NAS Module. Performing a manipulation results in heap-based buffer overflow. The attack may be initiated remotely. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability. | |
| Title | GL.iNet MT2500 APPS-NAS nas-web.get_file_list heap-based overflow | |
| First Time appeared |
Gl.inet
Gl.inet be3600 Gl.inet be6500 Gl.inet be9300 Gl.inet e5800 Gl.inet mt2500 Gl.inet mt3000 Gl.inet mt3600be Gl.inet mt5000 Gl.inet mt6000 Gl.inet x3000 Gl.inet xe3000 |
|
| Weaknesses | CWE-119 CWE-122 |
|
| CPEs | cpe:2.3:a:gl.inet:be3600:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:be6500:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:be9300:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:e5800:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:mt2500:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:mt3000:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:mt3600be:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:mt5000:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:mt6000:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:x3000:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:xe3000:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Gl.inet
Gl.inet be3600 Gl.inet be6500 Gl.inet be9300 Gl.inet e5800 Gl.inet mt2500 Gl.inet mt3000 Gl.inet mt3600be Gl.inet mt5000 Gl.inet mt6000 Gl.inet x3000 Gl.inet xe3000 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-03T05:15:07.982Z
Reserved: 2026-08-02T19:24:01.254Z
Link: CVE-2026-18585
No data.
No data.
No data.
OpenCVE Enrichment
No data.