ovpn-client.check_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Performing a manipulation of the argument filename results in command injection.This vulnerability is known as CVE-2026-18601. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
SOCIAL SHARE CARD GENERATOR