Executive brief
GL.iNet routers and mesh devices include a WebDAV file-sharing service that is used to store and synchronize files. A flaw in the COPY and MOVE functionality allows an attacker with access to a public share to bypass authorization checks and create, move, or overwrite files in private areas without authentication. This could lead to unauthorized data access, file corruption, or system compromise.
Technical details
The vulnerability is an authorization bypass in the WebDAV service's COPY and MOVE operations. The service correctly validates the source path but fails to perform the same authorization check on the attacker-controlled destination path. This allows an authenticated (or public) user to use a public writable share as a confused deputy to write or move files to restricted locations. Unauthenticated attackers can create, move, and overwrite private files in the WebDAV namespace that would normally return 401 Unauthorized on direct requests. The attack requires network access to the WebDAV service but does not require authentication. A patch is expected from the vendor; affected firmware versions are 4.5.x and later through 4.8.x.
Affected products
- GL.iNet A1300 4.5 to 4.8.x
- GL.iNet AX1800 4.5 to 4.8.x
- GL.iNet AXT1800 4.5 to 4.8.x
- GL.iNet BE1400 4.5 to 4.8.x
- GL.iNet BE3600 4.5 to 4.8.x
- GL.iNet BE6500 4.5 to 4.8.x
- GL.iNet BE9300 4.5 to 4.8.x
- GL.iNet BE10000 4.5 to 4.8.x
- GL.iNet E5800 4.5 to 4.8.x
- GL.iNet MT2500 4.5 to 4.8.x
- GL.iNet MT3000 4.5 to 4.8.x
- GL.iNet MT3600BE 4.5 to 4.8.x
- GL.iNet MT5000 4.5 to 4.8.x
- GL.iNet MT6000 4.5 to 4.8.x
- GL.iNet X2000 4.5 to 4.8.x
- GL.iNet X3000 4.5 to 4.8.x
- GL.iNet XE3000 4.5 to 4.8.x
Timeline
- 2026-08-17: disclosed
- 2026-08-17: advisory: CVE-2026-19979 published