Junglewise Threat Intelligence

CVE-2026-19980: GL.iNet Router Code Injection in Language Update

CVE-2026-19980 · Severity: high · CVSS 7.4 · Published 2026-08-17

Technologies: GL.iNet MT6000, GL.iNet X3000, GL.iNet MT2500, GL.iNet X2000, GL.iNet BE3600, GL.iNet E5800, GL.iNet BE10000, GL.iNet A1300, GL.iNet XE3000, GL.iNet BE1400, GL.iNet AX1800, GL.iNet MT3000, GL.iNet MT5000, GL.iNet AXT1800, GL.iNet MT3600BE. Vendors: GL.iNet.

Executive brief

GL.iNet routers include a language auto-update feature that is vulnerable to code injection attacks. An attacker can manipulate scheduling parameters in the language update function to inject and execute arbitrary commands with root privileges on the router, potentially enabling network compromise, credential theft, and lateral movement into connected networks.

Technical details

The vulnerability is a code injection flaw in the ui.update_langs RPC method of the Language Update component across GL.iNet router models. The vulnerable function accepts hour, min, and week parameters for scheduling automatic language updates but performs insufficient input validation—it checks only for parameter presence without enforcing numeric type constraints before writing values to gl_timer. An unauthenticated remote attacker can craft malicious requests with shell metacharacters or command injection payloads in these time fields, achieving arbitrary command execution with root privileges. The impact includes persistent router configuration modification, DNS/firewall/NAT manipulation, sensitive file access, and potential pivoting into connected networks. Patches are available via firmware updates above 4.8.x.

Affected products

  • GL.iNet A1300 4.6 through 4.8.x
  • GL.iNet AX1800 4.6 through 4.8.x
  • GL.iNet AXT1800 4.6 through 4.8.x
  • GL.iNet BE1400 4.6 through 4.8.x
  • GL.iNet BE3600 4.6 through 4.8.x
  • GL.iNet BE6500 4.6 through 4.8.x
  • GL.iNet BE9300 4.6 through 4.8.x
  • GL.iNet BE10000 4.6 through 4.8.x
  • GL.iNet E5800 4.6 through 4.8.x
  • GL.iNet MT2500 4.6 through 4.8.x
  • GL.iNet MT3000 4.6 through 4.8.x
  • GL.iNet MT3600BE 4.6 through 4.8.x
  • GL.iNet MT5000 4.6 through 4.8.x
  • GL.iNet MT6000 4.6 through 4.8.x
  • GL.iNet X2000 4.6 through 4.8.x
  • GL.iNet X3000 4.6 through 4.8.x
  • GL.iNet XE3000 4.6 through 4.8.x

Timeline

  • 2026-08-17: disclosed

References

Related threats