Executive brief
GL.iNet routers (sold for small office, home, and enterprise networks) contain a Wi-Fi Timer Power-Schedule feature that fails to validate user input. An attacker can inject arbitrary commands that execute with root privileges, allowing unauthorized access to sensitive configuration, network manipulation, and persistence on the device. Affected models range from budget units (A1300, AX1800) to high-end enterprise routers (BE10000, MT6000).
Technical details
The vulnerability is a command injection flaw in the Wi-Fi Timer Power-Schedule component. The affected code accepts user-supplied values for `switch_power` and `restore_power` parameters without proper validation or sanitization. These values are later written into root-level cron job entries, allowing an attacker to inject shell metacharacters and arbitrary commands. The attack requires network access to the router's management interface (typically remote via WAN or LAN) and no authentication bypass is needed if the interface is already exposed. A successful exploit grants arbitrary command execution as root, enabling complete device compromise, persistent backdoor installation, and lateral movement into connected networks.
Affected products
- GL.iNet A1300 up to 4.8.x
- GL.iNet AX1800 up to 4.8.x
- GL.iNet AXT1800 up to 4.8.x
- GL.iNet BE1400 up to 4.8.x
- GL.iNet BE3600 up to 4.8.x
- GL.iNet BE6500 up to 4.8.x
- GL.iNet BE9300 up to 4.8.x
- GL.iNet BE10000 up to 4.8.x
- GL.iNet E5800 up to 4.8.x
- GL.iNet MT2500 up to 4.8.x
- GL.iNet MT3000 up to 4.8.x
- GL.iNet MT3600BE up to 4.8.x
- GL.iNet MT5000 up to 4.8.x
- GL.iNet MT6000 up to 4.8.x
- GL.iNet X2000 up to 4.8.x
- GL.iNet X3000 up to 4.8.x
- GL.iNet XE3000 up to 4.8.x
Timeline
- 2026-08-17: disclosed