Junglewise Threat Intelligence

CVE-2026-19983: GL.iNet multiple routers OS command injection in NAS service

CVE-2026-19983 · Severity: high · CVSS 8.3 · Published 2026-08-17

Technologies: GL.iNet MT6000, GL.iNet X3000, GL.iNet MT2500, GL.iNet A1300, GL.iNet XE3000, GL.iNet AX1800, GL.iNet MT3000, GL.iNet AXT1800. Vendors: GL.iNet.

Executive brief

GL.iNet routers provide network storage (NAS) functionality through a service that listens on port 6000. A vulnerability in this service allows remote attackers to bypass authentication and execute arbitrary commands with root privileges without needing valid credentials. This could enable complete device compromise, data theft, or use of the router for further attacks on the network.

Technical details

The vulnerability exists in the NAS Command Service (/usr/bin/gl_nas_sys) and involves two chained weaknesses: (1) an authentication bypass in the NAS API token check that can be exploited by sending a Host header of 127.0.0.1, and (2) OS command injection in the GL_NAS_EXEC_FILE API endpoint through shell metacharacters in crafted filenames. The service becomes reachable on port 6000 when an administrator accesses the Network Storage feature in the web portal. No authentication is required; the attack is remotely exploitable from any network-reachable position. Successful exploitation results in unauthenticated remote code execution as root. Firmware version 4.9.0 and later address this issue.

Affected products

  • GL.iNet A1300 4.8.x
  • GL.iNet AX1800 4.8.x
  • GL.iNet AXT1800 4.8.x
  • GL.iNet MT2500 4.8.x
  • GL.iNet MT3000 4.8.x
  • GL.iNet MT6000 4.8.x
  • GL.iNet X3000 4.8.x
  • GL.iNet XE3000 4.8.x

Timeline

  • 2026-08-17: disclosed
  • 2026: patched: Version 4.9.0 and later address this issue

References

Related threats