References https://www.knowsafe.com/ti/info/0/1009280 https://bbs.kanxue.com/thread-284223.htm https://qkl.seebug.org/category/code-execution https://avd.aliyun.com/detail?id=AVD-2023-46454 https://app.opencve.io/cve/?vendor=gl-inet https://www.codeant.ai/vulnerability-database/cve-2026-26791 https://www.fortiguard.com/encyclopedia/ips/55170 https://www.knowsafe.com/ti/info/0/1009281 https://aleksazatezalo.medium.com/critical-command-injection-vulnerability-in-gl-inet-gl-axt1800-router-firmware-e6d67d81ee51 https://jvn.jp/en/vu/JVNVU93247159/ https://vuldb.com/vuln/369071 https://www.cve.org/CVERecord?id=CVE-2026-11451 https://nvd.nist.gov/vuln/detail/CVE-2026-11451 https://zhuanlan.zhihu.com/p/2017997433746010282 https://blog.csdn.net/weixin_44242297/article/details/127848954
Related VulnerabilitiesJuggle /h2-console 命令执行漏洞(CVE-2026-67208)PoCCVE-2026-12394: WordPress MemberGlut < 1.1.5 - Unauthenticated Privilege EscalationPoCCVE-2026-19478: GitLab CE/EE - GraphQL @gl_introduced Arbitrary Method InvocationPoCgoogle-api-key: Google API KeyPoCCVE-2026-53629: GLPI - Blind SQL Injection in History Log Filter (LogBleed)PoCCVE-2026-67208: Juggle <= 1.6.0 - Unauthenticated Exposed H2 Database ConsoleWP Google 地图 < 9.0.48 - 未经身份验证的存储 XSS (CVE-2025-11307)PoCCVE-2026-8732: WP Maps Pro (wp-google-map-gold) <= 6.1.0 - Unauthenticated Administrator Account CreationPalo Alto Networks PAN-OS GlobalProtect /ssl-vpn/login.esp 权限绕过漏洞(CVE-2026-0257)厦门四信水利信息化平台接口configList存在sql注入漏洞Glowroot /backend/admin/users 未授权访问漏洞PoCCVE-2026-21484: AnythingLLM - Username Enumeration via Password RecoveryPoCCVE-2026-4810: Google ADK-Python - Unauthenticated Builder Endpoint