Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-19981

GL.iNet Wi-Fi Timer Power-Schedule OS command injection

OS command injection via switch_power/restore_power arguments in GL.iNet's Wi-Fi Timer Power-Schedule feature affects seventeen 4.8.x device models; remotely exploitable, PoC public.

cat cve-2026-19981.json
Vendor
GL.iNet
Product
A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000, XE3000 (firmware 4.8.x and earlier)
CVSS
7.4
EPSS (exploit probability)
N/A
Status
patched
Published

The Wi-Fi Timer Power-Schedule feature on affected GL.iNet devices passes unsanitized switch_power and restore_power arguments to OS-level execution, enabling command injection. Seventeen device models across the GL.iNet line are in scope.

GL.iNet confirmed the flaw and patched it in firmware 4.9.0. Public PoC is available. See the full GL.iNet advisory batch for all five CVEs in this release.