<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — GL.iNet</title><description>Security vulnerabilities in GL.iNet routers and gateway devices — a popular line of OpenWRT-based SOHO, travel, and prosumer edge appliances including the MT3000, AX1800, MT6000, and Beryl/Slate/Opal series. GL.iNet devices frequently appear at network edges in small offices, remote work setups, and infrastructure deployments. Combined article + CVE feed for the GL.iNet beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>GL.iNet 4.9.0 Fixes Five RCE Flaws in Wi-Fi Routers</title><link>https://0daynews.com/articles/2026-08-17-gl-inet-490-rce-flaws-routers/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-17-gl-inet-490-rce-flaws-routers/</guid><description>GL.iNet confirmed five high-severity RCE and auth bypass vulnerabilities across its 4.8.x firmware line. Version 4.9.0 is the fix for all affected devices.</description><pubDate>Mon, 17 Aug 2026 06:00:00 GMT</pubDate><category>GL.iNet</category><category>article</category></item><item><title>CVE-2026-19979 — GL.iNet WebDAV COPY/MOVE authorization bypass allows out-of-scope file access</title><link>https://0daynews.com/cve/cve-2026-19979/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-19979/</guid><description>Authorization bypass in GL.iNet&apos;s WebDAV service COPY and MOVE operations lets remote attackers access files outside the designated public share scope on a wide range of 4.8.x devices.</description><pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate><category>GL.iNet</category><category>high</category><category>cve</category></item><item><title>CVE-2026-19980 — GL.iNet language auto-update code injection via cron arguments</title><link>https://0daynews.com/cve/cve-2026-19980/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-19980/</guid><description>Code injection in GL.iNet&apos;s ui.update_langs function via hour/min/week arguments in the language update scheduler; affects seventeen 4.8.x models, remotely exploitable, PoC public.</description><pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate><category>GL.iNet</category><category>high</category><category>cve</category></item><item><title>CVE-2026-19981 — GL.iNet Wi-Fi Timer Power-Schedule OS command injection</title><link>https://0daynews.com/cve/cve-2026-19981/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-19981/</guid><description>OS command injection via switch_power/restore_power arguments in GL.iNet&apos;s Wi-Fi Timer Power-Schedule feature affects seventeen 4.8.x device models; remotely exploitable, PoC public.</description><pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate><category>GL.iNet</category><category>high</category><category>cve</category></item><item><title>CVE-2026-19982 — GL.iNet firewall-management RPC OS command injection</title><link>https://0daynews.com/cve/cve-2026-19982/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-19982/</guid><description>OS command injection via dest_port/dest_ip arguments in GL.iNet&apos;s firewall-management RPC on BE9300 and MT6000 devices running firmware 4.8.x; remotely exploitable, PoC public.</description><pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate><category>GL.iNet</category><category>high</category><category>cve</category></item><item><title>CVE-2026-19983 — GL.iNet NAS command service unauthenticated root RCE via host-header bypass</title><link>https://0daynews.com/cve/cve-2026-19983/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-19983/</guid><description>Unauthenticated host-header manipulation in GL.iNet&apos;s NAS command service enables remote code execution as root on A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000, XE3000 running 4.8.x.</description><pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate><category>GL.iNet</category><category>high</category><category>cve</category></item></channel></rss>