CyberRota
← Ana sayfaya dön

CVE-2026-12187

HIGH · CVSS 8.8 EPSS %1.94 Public Exploit

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-06-14T23:16:34.853 · Çekilme zamanı: 2026-06-30T18:21:11.745699+00:00

CyberRota Yorumu

Uzaktan istismar edilebilir olabilir.

Public Exploit Sinyali

Bu CVE için açıklama veya referanslarda public exploit / PoC / GitHub / Metasploit sinyali tespit edildi.

Tespit Edilen Sinyaller
exploit
GitHub PoC Linkleri

Not: Bu bağlantılar yalnızca güvenlik araştırması ve doğrulama amacıyla listelenmiştir.

CVE
CVE-2026-12187
Severity
HIGH
CVSS
8.8
EPSS
%1.94

Orijinal NVD Açıklaması

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Affected by this vulnerability is an unknown functionality of the file /usr/bin/one_click_upgrade of the component Online Firmware Upgrade Handler. Such manipulation leads to command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 4.7 addresses this issue. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.