Skip to content
feed: live
>_0dayNews
← All vendors
Vendor

GL.iNet

Security vulnerabilities in GL.iNet routers and gateway devices — a popular line of OpenWRT-based SOHO, travel, and prosumer edge appliances including the MT3000, AX1800, MT6000, and Beryl/Slate/Opal series. GL.iNet devices frequently appear at network edges in small offices, remote work setups, and infrastructure deployments.

5 CVEs1 articlesRSS
CVEs
CVE-2026-19979
[ HIGH ]CVSS 8.3patched

GL.iNet WebDAV COPY/MOVE authorization bypass allows out-of-scope file access

Authorization bypass in GL.iNet's WebDAV service COPY and MOVE operations lets remote attackers access files outside the designated public share scope on a wide range of 4.8.x devices.

GL.iNet / A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000, XE3000 (firmware 4.8.x and earlier)
CVE-2026-19980
[ HIGH ]CVSS 7.4patched

GL.iNet language auto-update code injection via cron arguments

Code injection in GL.iNet's ui.update_langs function via hour/min/week arguments in the language update scheduler; affects seventeen 4.8.x models, remotely exploitable, PoC public.

GL.iNet / A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000, XE3000 (firmware 4.8.x and earlier)
CVE-2026-19981
[ HIGH ]CVSS 7.4patched

GL.iNet Wi-Fi Timer Power-Schedule OS command injection

OS command injection via switch_power/restore_power arguments in GL.iNet's Wi-Fi Timer Power-Schedule feature affects seventeen 4.8.x device models; remotely exploitable, PoC public.

GL.iNet / A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000, XE3000 (firmware 4.8.x and earlier)
CVE-2026-19982
[ HIGH ]CVSS 7.4patched

GL.iNet firewall-management RPC OS command injection

OS command injection via dest_port/dest_ip arguments in GL.iNet's firewall-management RPC on BE9300 and MT6000 devices running firmware 4.8.x; remotely exploitable, PoC public.

GL.iNet / BE9300, MT6000 (firmware 4.8.x and earlier)
CVE-2026-19983
[ HIGH ]CVSS 8.3patched

GL.iNet NAS command service unauthenticated root RCE via host-header bypass

Unauthenticated host-header manipulation in GL.iNet's NAS command service enables remote code execution as root on A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000, XE3000 running 4.8.x.

GL.iNet / A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000, XE3000 (firmware 4.8.x and earlier)
Articles