CVE Record
[ HIGH ]CVE-2026-19980
GL.iNet language auto-update code injection via cron arguments
Code injection in GL.iNet's ui.update_langs function via hour/min/week arguments in the language update scheduler; affects seventeen 4.8.x models, remotely exploitable, PoC public.
- Vendor
- GL.iNet
- Product
- A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000, XE3000 (firmware 4.8.x and earlier)
- CVSS
- 7.4
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
GL.iNet’s ui.update_langs function in the language auto-update component fails to sanitize hour, min, and week scheduling arguments. A remote attacker can inject code through these parameters, exploiting the way the scheduler passes values to the underlying system.
GL.iNet confirmed the vulnerability and released firmware 4.9.0 as the fix. Public PoC is available. See the full GL.iNet advisory batch for all five CVEs patched in this release.
