{"schema_version":1,"title":"GL.iNet MT3000 (Beryl AX) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 6 vulnerabilities in GL.iNet MT3000 (Beryl AX): 0 in the last 7 days and 4 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-19983, was published on 17 August 2026.","url":"https://junglewise.ai/threats/technologies/mt3000","json_url":"https://junglewise.ai/threats/technologies/mt3000.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/mt3000","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":4,"all_time":6,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":4,"last_365_days":6},"latest":[{"cve":"CVE-2026-19983","cvss":8.3,"epss":0.0206,"slug":"cve-2026-19983-gl-inet-multiple-routers-os-command-injection-in-nas-service","title":"GL.iNet multiple routers OS command injection in NAS service","severity":"high","exploited":false,"published_at":"2026-08-17T05:17:09.947+00:00","url":"https://junglewise.ai/threats/cve-2026-19983-gl-inet-multiple-routers-os-command-injection-in-nas-service"},{"cve":"CVE-2026-19981","cvss":7.4,"epss":0.0177,"slug":"cve-2026-19981-gl-inet-router-os-command-injection-in-wi-fi-timer-power-schedule","title":"GL.iNet Router OS command injection in Wi-Fi Timer Power-Schedule","severity":"high","exploited":false,"published_at":"2026-08-17T04:16:56.6+00:00","url":"https://junglewise.ai/threats/cve-2026-19981-gl-inet-router-os-command-injection-in-wi-fi-timer-power-schedule"},{"cve":"CVE-2026-19980","cvss":7.4,"epss":0.0039,"slug":"cve-2026-19980-gl-inet-router-code-injection-in-language-update","title":"GL.iNet Router Code Injection in Language Update","severity":"high","exploited":false,"published_at":"2026-08-17T04:16:56.25+00:00","url":"https://junglewise.ai/threats/cve-2026-19980-gl-inet-router-code-injection-in-language-update"},{"cve":"CVE-2026-19979","cvss":8.3,"epss":0.0054,"slug":"cve-2026-19979-gl-inet-webdav-authorization-bypass-in-copy-move","title":"GL.iNet WebDAV authorization bypass in COPY/MOVE","severity":"high","exploited":false,"published_at":"2026-08-17T04:16:55.693+00:00","url":"https://junglewise.ai/threats/cve-2026-19979-gl-inet-webdav-authorization-bypass-in-copy-move"},{"cve":"CVE-2026-11505","cvss":5,"slug":"cve-2026-11505-gl-inet-routers-hard-coded-authentication-token-in-glnassys","title":"GL.iNet Routers hard-coded authentication token in glnassys","severity":"medium","exploited":false,"published_at":"2026-06-08T12:16:30.747+00:00","url":"https://junglewise.ai/threats/cve-2026-11505-gl-inet-routers-hard-coded-authentication-token-in-glnassys"},{"cve":"CVE-2026-11406","cvss":6.3,"slug":"cve-2026-11406-gl-inet-mt3000-command-injection-in-openvpn-client-import","title":"GL.iNet MT3000 command injection in OpenVPN Client Import Workflow","severity":"medium","exploited":false,"published_at":"2026-06-06T10:16:27.017+00:00","url":"https://junglewise.ai/threats/cve-2026-11406-gl-inet-mt3000-command-injection-in-openvpn-client-import"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"GL.iNet GL-MT3000","slug":"gl-mt3000","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/gl-mt3000"},{"name":"GL.iNet AX1800 (Flint)","slug":"ax1800","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/ax1800"},{"name":"GL.iNet MT6000 (Flint 2)","slug":"mt6000","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/mt6000"},{"name":"GL.iNet A1300 (Slate Plus)","slug":"a1300","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/a1300"},{"name":"GL.iNet AXT1800 (Slate AX)","slug":"axt1800","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/axt1800"},{"name":"GL.iNet MT2500 (Brume 2)","slug":"mt2500","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/mt2500"},{"name":"GL.iNet X3000 (Spitz AX)","slug":"x3000","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/x3000"},{"name":"GL.iNet XE3000 (Puli AX)","slug":"xe3000","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/xe3000"},{"name":"GL.iNet BE10000","slug":"be10000","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/be10000"},{"name":"GL.iNet BE1400","slug":"be1400","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/be1400"},{"name":"GL.iNet BE3600","slug":"be3600","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/be3600"},{"name":"GL.iNet E5800","slug":"e5800","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/e5800"}],"technology":{"hub":true,"name":"GL.iNet MT3000 (Beryl AX)","slug":"mt3000","vendor":{"name":"GL.iNet","slug":"gl-inet","url":"https://junglewise.ai/threats/vendors/gl-inet"},"aliases":[],"category":"firmware","homepage":"https://www.gl-inet.com/products/gl-mt3000/","repo_url":"https://www.gl-inet.com/products/gl-mt3000/","description":"Firmware for the GL-MT3000 (Beryl AX) Wi-Fi 6 travel router.","url":"https://junglewise.ai/threats/technologies/mt3000"},"most_severe":[{"cve":"CVE-2026-19983","cvss":8.3,"epss":0.0206,"slug":"cve-2026-19983-gl-inet-multiple-routers-os-command-injection-in-nas-service","title":"GL.iNet multiple routers OS command injection in NAS service","severity":"high","exploited":false,"published_at":"2026-08-17T05:17:09.947+00:00","url":"https://junglewise.ai/threats/cve-2026-19983-gl-inet-multiple-routers-os-command-injection-in-nas-service"},{"cve":"CVE-2026-19979","cvss":8.3,"epss":0.0054,"slug":"cve-2026-19979-gl-inet-webdav-authorization-bypass-in-copy-move","title":"GL.iNet WebDAV authorization bypass in COPY/MOVE","severity":"high","exploited":false,"published_at":"2026-08-17T04:16:55.693+00:00","url":"https://junglewise.ai/threats/cve-2026-19979-gl-inet-webdav-authorization-bypass-in-copy-move"},{"cve":"CVE-2026-19981","cvss":7.4,"epss":0.0177,"slug":"cve-2026-19981-gl-inet-router-os-command-injection-in-wi-fi-timer-power-schedule","title":"GL.iNet Router OS command injection in Wi-Fi Timer Power-Schedule","severity":"high","exploited":false,"published_at":"2026-08-17T04:16:56.6+00:00","url":"https://junglewise.ai/threats/cve-2026-19981-gl-inet-router-os-command-injection-in-wi-fi-timer-power-schedule"},{"cve":"CVE-2026-19980","cvss":7.4,"epss":0.0039,"slug":"cve-2026-19980-gl-inet-router-code-injection-in-language-update","title":"GL.iNet Router Code Injection in Language Update","severity":"high","exploited":false,"published_at":"2026-08-17T04:16:56.25+00:00","url":"https://junglewise.ai/threats/cve-2026-19980-gl-inet-router-code-injection-in-language-update"},{"cve":"CVE-2026-11406","cvss":6.3,"slug":"cve-2026-11406-gl-inet-mt3000-command-injection-in-openvpn-client-import","title":"GL.iNet MT3000 command injection in OpenVPN Client Import Workflow","severity":"medium","exploited":false,"published_at":"2026-06-06T10:16:27.017+00:00","url":"https://junglewise.ai/threats/cve-2026-11406-gl-inet-mt3000-command-injection-in-openvpn-client-import"},{"cve":"CVE-2026-11505","cvss":5,"slug":"cve-2026-11505-gl-inet-routers-hard-coded-authentication-token-in-glnassys","title":"GL.iNet Routers hard-coded authentication token in glnassys","severity":"medium","exploited":false,"published_at":"2026-06-08T12:16:30.747+00:00","url":"https://junglewise.ai/threats/cve-2026-11505-gl-inet-routers-hard-coded-authentication-token-in-glnassys"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}