CVE Record
[ HIGH ]CVE-2026-19981
GL.iNet Wi-Fi Timer Power-Schedule OS command injection
OS command injection via switch_power/restore_power arguments in GL.iNet's Wi-Fi Timer Power-Schedule feature affects seventeen 4.8.x device models; remotely exploitable, PoC public.
- Vendor
- GL.iNet
- Product
- A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000, XE3000 (firmware 4.8.x and earlier)
- CVSS
- 7.4
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
The Wi-Fi Timer Power-Schedule feature on affected GL.iNet devices passes unsanitized switch_power and restore_power arguments to OS-level execution, enabling command injection. Seventeen device models across the GL.iNet line are in scope.
GL.iNet confirmed the flaw and patched it in firmware 4.9.0. Public PoC is available. See the full GL.iNet advisory batch for all five CVEs in this release.
