Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-19982

GL.iNet firewall-management RPC OS command injection

OS command injection via dest_port/dest_ip arguments in GL.iNet's firewall-management RPC on BE9300 and MT6000 devices running firmware 4.8.x; remotely exploitable, PoC public.

cat cve-2026-19982.json
Vendor
GL.iNet
Product
BE9300, MT6000 (firmware 4.8.x and earlier)
CVSS
7.4
EPSS (exploit probability)
N/A
Status
patched
Published

The firewall-management RPC component on the GL.iNet BE9300 and MT6000 fails to sanitize the dest_port and dest_ip arguments before passing them to an OS-level call. A remote attacker can inject arbitrary commands by manipulating these values.

GL.iNet confirmed the vulnerability and fixed it in firmware 4.9.0. Public PoC exists. See the full GL.iNet advisory batch for all five flaws patched in this release.