Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-19983

GL.iNet NAS command service unauthenticated root RCE via host-header bypass

Unauthenticated host-header manipulation in GL.iNet's NAS command service enables remote code execution as root on A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000, XE3000 running 4.8.x.

cat cve-2026-19983.json
Vendor
GL.iNet
Product
A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000, XE3000 (firmware 4.8.x and earlier)
CVSS
8.3
EPSS (exploit probability)
N/A
Status
patched
Published

GL.iNet confirmed this vulnerability in its NAS command service (/usr/bin/gl_nas_sys). A manipulated host header in requests to the service bypasses session validation and allows an unauthenticated remote attacker to execute commands as root. No credentials or prior access are required.

The vendor confirmed the issue exists and fixed it in firmware 4.9.0. Update immediately — this is the most severe of the five flaws patched in this release cycle. See the full GL.iNet advisory batch for context on the complete patch set.