Executive brief
A security vulnerability exists in several GL.iNet router models due to the use of a hard-coded authentication token within the network storage component. This flaw allows an attacker to bypass security measures and interact with storage interfaces, potentially leading to unauthorized access to files or the ability to run malicious commands on the device. This could result in the theft of sensitive data stored on the router or a complete compromise of the device's operations.
Technical details
A vulnerability (CWE-321) exists in the glnassys component of GL.iNet firmware version 4.8.x across multiple router models. The software utilizes a hard-coded default authentication token for network storage interfaces. A remote attacker with low privileges can exploit this by providing the static token to call sensitive storage-related APIs. Successful exploitation can lead to unauthorized access and arbitrary command execution on the underlying operating system. The attack is considered high complexity due to specific environmental or timing requirements. The issue is addressed in firmware version 4.9.0.
Affected products
- GL.iNet A1300 4.8.x
- GL.iNet AX1800 4.8.x
- GL.iNet AXT1800 4.8.x
- GL.iNet MT2500 4.8.x
- GL.iNet MT3000 4.8.x
- GL.iNet MT6000 4.8.x
- GL.iNet X3000 4.8.x
- GL.iNet XE3000 4.8.x
Timeline
- 2026-06-08: disclosed
- 2026-06-08: advisory
References
- https://cloud-static-test.gl-inet.cn/security/openwrt-ipq60xx-glinet_ax1800-squashfs-sysupgrade.tar
- https://github.com/gl-inet/CVE-issues/blob/main/4.0.0/The%20hard%20coded%20default%20authentication%20token%20in%20gl%20nas%20sys%20poses%20a%20risk%20to%20unauthorized%20command%20execution.md
- https://vuldb.com/cve/CVE-2026-11505
- https://vuldb.com/submit/835698
- https://vuldb.com/vuln/369125
- https://vuldb.com/vuln/369125/cti