📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Industrial Control Systems / Manufacturing HIGH 1h Global vulnerability Software/Cloud Services HIGH 1h Global vulnerability Network Infrastructure HIGH 2h Global vulnerability Mobile Device Management / Enterprise Security CRITICAL 2h Global vulnerability Operating Systems/Security Software CRITICAL 3h Global vulnerability Software Development and Technology CRITICAL 3h Global general Technology/AI Services LOW 6h Global vulnerability Information Technology CRITICAL 9h Global vulnerability Information Technology CRITICAL 10h Global vulnerability Software and Technology HIGH 11h Global vulnerability Industrial Control Systems / Manufacturing HIGH 1h Global vulnerability Software/Cloud Services HIGH 1h Global vulnerability Network Infrastructure HIGH 2h Global vulnerability Mobile Device Management / Enterprise Security CRITICAL 2h Global vulnerability Operating Systems/Security Software CRITICAL 3h Global vulnerability Software Development and Technology CRITICAL 3h Global general Technology/AI Services LOW 6h Global vulnerability Information Technology CRITICAL 9h Global vulnerability Information Technology CRITICAL 10h Global vulnerability Software and Technology HIGH 11h Global vulnerability Industrial Control Systems / Manufacturing HIGH 1h Global vulnerability Software/Cloud Services HIGH 1h Global vulnerability Network Infrastructure HIGH 2h Global vulnerability Mobile Device Management / Enterprise Security CRITICAL 2h Global vulnerability Operating Systems/Security Software CRITICAL 3h Global vulnerability Software Development and Technology CRITICAL 3h Global general Technology/AI Services LOW 6h Global vulnerability Information Technology CRITICAL 9h Global vulnerability Information Technology CRITICAL 10h Global vulnerability Software and Technology HIGH 11h
Vulnerabilities

CVE-2026-11406

Medium
CWE-74 — Weakness Type
Published: Jun 6, 2026  ·  Modified: Jun 9, 2026  ·  Source: NVD
CVSS v3
6.3
🔗 NVD Official
📄 Description (English)

A vulnerability was determined in GL.iNet MT3000 up to 4.4.5. This vulnerability affects unknown code of the file ovpnclient.sh of the component OpenVPN Client Import Workflow. This manipulation causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 4.9.0_beta3-1012-0513-1778656146 is able to resolve this issue. You should upgrade the affected component. The vendor confirms: "This issue has been addressed by implementing malicious checks on OpenVPN configuration files to prevent command injection attacks carried through malicious configuration files."

🤖 AI Executive Summary

GL.iNet MT3000 routers up to version 4.4.5 contain a command injection vulnerability in the OpenVPN Client Import Workflow that allows remote exploitation through malicious configuration files. While a beta patch (4.9.0_beta3) exists, no stable release is currently available. This vulnerability poses significant risk to organizations using GL.iNet devices for VPN connectivity, particularly in Saudi Arabia's government and enterprise sectors.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Jun 6, 2026 14:32
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability primarily impacts Saudi government agencies, financial institutions, and enterprises using GL.iNet MT3000 routers for secure VPN connectivity. High-risk sectors include: (1) Government/NCA - remote access infrastructure for critical operations; (2) Banking/SAMA - VPN gateways for inter-bank communications and regulatory reporting; (3) Telecom/STC - network infrastructure and customer VPN services; (4) Energy/ARAMCO - remote access for operational technology networks; (5) Healthcare - telemedicine and secure data transmission. Attackers could execute arbitrary commands with router privileges, potentially compromising entire network segments and sensitive data.
🏢 Affected Saudi Sectors
Government/NCA Banking/SAMA Telecom/STC Energy/ARAMCO Healthcare Enterprise IT Infrastructure Defense/Military
⚖️ Saudi Risk Score (AI)
7.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Inventory all GL.iNet MT3000 devices running firmware versions up to 4.4.5 across your organization
2. Restrict OpenVPN client import functionality to trusted administrators only
3. Implement network segmentation to isolate affected routers from critical systems
4. Monitor router logs for suspicious OpenVPN configuration import attempts

PATCHING GUIDANCE:
1. Evaluate beta version 4.9.0_beta3-1012-0513-1778656146 in isolated test environment before production deployment
2. Contact GL.iNet support for stable release timeline and security advisories
3. Plan firmware upgrade during maintenance windows with rollback procedures

COMPENSATING CONTROLS (if patching delayed):
1. Disable OpenVPN client import feature via web interface if not required
2. Implement firewall rules to restrict access to router management interfaces (port 80/443) to authorized IPs only
3. Use VPN configuration validation scripts to sanitize inputs before import
4. Deploy intrusion detection signatures for command injection patterns in OpenVPN configs

DETECTION RULES:
1. Monitor for unusual process execution spawned from ovpnclient.sh (bash, sh, nc, curl, wget)
2. Alert on OpenVPN configuration files containing shell metacharacters (;, |, &, $(), backticks)
3. Track failed and successful OpenVPN client imports with detailed logging
4. Monitor outbound connections initiated from router processes post-import
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. قم بحصر جميع أجهزة GL.iNet MT3000 التي تعمل بإصدارات البرامج الثابتة حتى 4.4.5 في جميع أنحاء مؤسستك
2. قيد وظيفة استيراد عميل OpenVPN للمسؤولين الموثوقين فقط
3. طبق تقسيم الشبكة لعزل الأجهزة المتأثرة عن الأنظمة الحرجة
4. راقب سجلات الجهاز للكشف عن محاولات استيراد تكوين OpenVPN المريبة

إرشادات التصحيح:
1. قيّم الإصدار التجريبي 4.9.0_beta3 في بيئة اختبار معزولة قبل النشر في الإنتاج
2. اتصل بدعم GL.iNet للحصول على جدول الإصدار المستقر والتنبيهات الأمنية
3. خطط لترقية البرامج الثابتة خلال نوافذ الصيانة مع إجراءات التراجع

الضوابط البديلة (إذا تأخر التصحيح):
1. عطّل ميزة استيراد عميل OpenVPN عبر واجهة الويب إذا لم تكن مطلوبة
2. طبق قواعد جدار الحماية لتقييد الوصول إلى واجهات إدارة الجهاز (المنفذ 80/443) إلى عناوين IP المصرح بها فقط
3. استخدم نصوص التحقق من صحة تكوين VPN لتنظيف المدخلات قبل الاستيراد
4. نشر توقيعات كشف الاختراق لأنماط حقن الأوامر في تكوينات OpenVPN

قواعد الكشف:
1. راقب تنفيذ العمليات غير العادية التي تنشأ من ovpnclient.sh
2. أصدر تنبيهات على ملفات تكوين OpenVPN التي تحتوي على أحرف shell metacharacters
3. تتبع عمليات استيراد عميل OpenVPN الفاشلة والناجحة مع تسجيل مفصل
4. راقب الاتصالات الصادرة التي تبدأ من عمليات الجهاز بعد الاستيراد
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.5.1.1 - Information Security Policies (secure configuration management) ECC 2024 A.8.1.1 - User Endpoint Devices (VPN device security) ECC 2024 A.12.6.1 - Management of Technical Vulnerabilities (patch management) ECC 2024 A.14.2.1 - Secure Development Policy (secure coding practices)
🔵 SAMA CSF
SAMA CSF ID.GV-1 - Organizational Context (asset inventory and management) SAMA CSF PR.IP-12 - Information and Communication Technology (ICT) Security (vulnerability management) SAMA CSF DE.CM-4 - Malicious Code Detection (command injection detection) SAMA CSF RS.MI-2 - Incident Response (containment and eradication)
🟡 ISO 27001:2022
ISO 27001:2022 A.5.1 - Policies for Information Security (configuration management policy) ISO 27001:2022 A.8.1 - User Endpoint Devices (secure device configuration) ISO 27001:2022 A.12.6 - Management of Technical Vulnerabilities and Exposures (patch management) ISO 27001:2022 A.14.2 - Secure Development, Implementation and Maintenance (secure coding)
🟣 PCI DSS v4.0.1
PCI DSS 6.2 - Ensure all system components and software are protected from known vulnerabilities PCI DSS 11.2 - Run automated vulnerability scanning tools regularly
📊 CVSS Score
6.3
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityL — Low / Local
IntegrityL — Low / Local
AvailabilityL — Low / Local
📋 Quick Facts
Severity Medium
CVSS Score6.3
CWECWE-74
EPSS0.73%
Exploit No
Patch ✗ No
Published 2026-06-06
Source Feed nvd
🇸🇦 Saudi Risk Score
7.2
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-74
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.