Junglewise Threat Intelligence

CVE-2026-19981: GL.iNet Router OS command injection in Wi-Fi Timer Power-Schedule

CVE-2026-19981 · Severity: high · CVSS 7.4 · Published 2026-08-17

Technologies: GL.iNet X2000, GL.iNet BE10000, GL.iNet E5800, GL.iNet MT5000, GL.iNet MT6000, GL.iNet BE1400, GL.iNet X3000, GL.iNet MT2500, GL.iNet A1300, GL.iNet XE3000, GL.iNet MT3600BE, GL.iNet AX1800, GL.iNet MT3000, GL.iNet AXT1800, GL.iNet BE3600. Vendors: GL.iNet.

Executive brief

GL.iNet routers (sold for small office, home, and enterprise networks) contain a Wi-Fi Timer Power-Schedule feature that fails to validate user input. An attacker can inject arbitrary commands that execute with root privileges, allowing unauthorized access to sensitive configuration, network manipulation, and persistence on the device. Affected models range from budget units (A1300, AX1800) to high-end enterprise routers (BE10000, MT6000).

Technical details

The vulnerability is a command injection flaw in the Wi-Fi Timer Power-Schedule component. The affected code accepts user-supplied values for `switch_power` and `restore_power` parameters without proper validation or sanitization. These values are later written into root-level cron job entries, allowing an attacker to inject shell metacharacters and arbitrary commands. The attack requires network access to the router's management interface (typically remote via WAN or LAN) and no authentication bypass is needed if the interface is already exposed. A successful exploit grants arbitrary command execution as root, enabling complete device compromise, persistent backdoor installation, and lateral movement into connected networks.

Affected products

  • GL.iNet A1300 up to 4.8.x
  • GL.iNet AX1800 up to 4.8.x
  • GL.iNet AXT1800 up to 4.8.x
  • GL.iNet BE1400 up to 4.8.x
  • GL.iNet BE3600 up to 4.8.x
  • GL.iNet BE6500 up to 4.8.x
  • GL.iNet BE9300 up to 4.8.x
  • GL.iNet BE10000 up to 4.8.x
  • GL.iNet E5800 up to 4.8.x
  • GL.iNet MT2500 up to 4.8.x
  • GL.iNet MT3000 up to 4.8.x
  • GL.iNet MT3600BE up to 4.8.x
  • GL.iNet MT5000 up to 4.8.x
  • GL.iNet MT6000 up to 4.8.x
  • GL.iNet X2000 up to 4.8.x
  • GL.iNet X3000 up to 4.8.x
  • GL.iNet XE3000 up to 4.8.x

Timeline

  • 2026-08-17: disclosed

References

Related threats