Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-19980

GL.iNet language auto-update code injection via cron arguments

Code injection in GL.iNet's ui.update_langs function via hour/min/week arguments in the language update scheduler; affects seventeen 4.8.x models, remotely exploitable, PoC public.

cat cve-2026-19980.json
Vendor
GL.iNet
Product
A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000, XE3000 (firmware 4.8.x and earlier)
CVSS
7.4
EPSS (exploit probability)
N/A
Status
patched
Published

GL.iNet’s ui.update_langs function in the language auto-update component fails to sanitize hour, min, and week scheduling arguments. A remote attacker can inject code through these parameters, exploiting the way the scheduler passes values to the underlying system.

GL.iNet confirmed the vulnerability and released firmware 4.9.0 as the fix. Public PoC is available. See the full GL.iNet advisory batch for all five CVEs patched in this release.