{"schema_version":1,"title":"GL.iNet vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 19 vulnerabilities in GL.iNet: 0 in the last 7 days and 9 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-19983, was published on 17 August 2026. 16 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/gl-inet","json_url":"https://junglewise.ai/threats/vendors/gl-inet.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/gl-inet","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":11,"all_time":19,"critical":3,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":9,"last_365_days":19},"latest":[{"cve":"CVE-2026-19983","cvss":8.3,"epss":0.0206,"slug":"cve-2026-19983-gl-inet-multiple-routers-os-command-injection-in-nas-service","title":"GL.iNet multiple routers OS command injection in NAS service","severity":"high","exploited":false,"published_at":"2026-08-17T05:17:09.947+00:00","url":"https://junglewise.ai/threats/cve-2026-19983-gl-inet-multiple-routers-os-command-injection-in-nas-service"},{"cve":"CVE-2026-19982","cvss":7.4,"epss":0.0177,"slug":"cve-2026-19982-gl-inet-be9300-and-mt6000-os-command-injection-in-firewall","title":"GL.iNet BE9300 and MT6000 OS command injection in firewall-management RPC","severity":"high","exploited":false,"published_at":"2026-08-17T05:17:09.767+00:00","url":"https://junglewise.ai/threats/cve-2026-19982-gl-inet-be9300-and-mt6000-os-command-injection-in-firewall"},{"cve":"CVE-2026-19981","cvss":7.4,"epss":0.0177,"slug":"cve-2026-19981-gl-inet-router-os-command-injection-in-wi-fi-timer-power-schedule","title":"GL.iNet Router OS command injection in Wi-Fi Timer Power-Schedule","severity":"high","exploited":false,"published_at":"2026-08-17T04:16:56.6+00:00","url":"https://junglewise.ai/threats/cve-2026-19981-gl-inet-router-os-command-injection-in-wi-fi-timer-power-schedule"},{"cve":"CVE-2026-19980","cvss":7.4,"epss":0.0039,"slug":"cve-2026-19980-gl-inet-router-code-injection-in-language-update","title":"GL.iNet Router Code Injection in Language Update","severity":"high","exploited":false,"published_at":"2026-08-17T04:16:56.25+00:00","url":"https://junglewise.ai/threats/cve-2026-19980-gl-inet-router-code-injection-in-language-update"},{"cve":"CVE-2026-19979","cvss":8.3,"epss":0.0054,"slug":"cve-2026-19979-gl-inet-webdav-authorization-bypass-in-copy-move","title":"GL.iNet WebDAV authorization bypass in COPY/MOVE","severity":"high","exploited":false,"published_at":"2026-08-17T04:16:55.693+00:00","url":"https://junglewise.ai/threats/cve-2026-19979-gl-inet-webdav-authorization-bypass-in-copy-move"},{"cve":"CVE-2026-18787","cvss":8.8,"epss":0.0321,"slug":"cve-2026-18787-gl-inet-ax1800-command-injection-in-rpc-endpoint","title":"GL.iNet AX1800 command injection in RPC endpoint","severity":"high","exploited":false,"published_at":"2026-08-04T17:16:48.817+00:00","url":"https://junglewise.ai/threats/cve-2026-18787-gl-inet-ax1800-command-injection-in-rpc-endpoint"},{"cve":"CVE-2026-18616","cvss":9.8,"epss":0.0362,"slug":"cve-2026-18616-gl-inet-gl-mt3000-command-injection-in-wg-server","title":"GL-iNet GL-MT3000 command injection in wg-server","severity":"critical","exploited":false,"published_at":"2026-08-03T19:16:45.557+00:00","url":"https://junglewise.ai/threats/cve-2026-18616-gl-inet-gl-mt3000-command-injection-in-wg-server"},{"cve":"CVE-2026-18615","cvss":9.8,"epss":0.0362,"slug":"cve-2026-18615-gl-inet-gl-mt3000-command-injection-in-wg-server","title":"GL-iNet GL-MT3000 command injection in wg-server","severity":"critical","exploited":false,"published_at":"2026-08-03T19:16:45.383+00:00","url":"https://junglewise.ai/threats/cve-2026-18615-gl-inet-gl-mt3000-command-injection-in-wg-server"},{"cve":"CVE-2026-18614","cvss":9.8,"epss":0.0362,"slug":"cve-2026-18614-gl-inet-gl-mt3000-command-injection-in-s2s-so","title":"GL-iNet GL-MT3000 command injection in s2s.so","severity":"critical","exploited":false,"published_at":"2026-08-03T19:16:45.2+00:00","url":"https://junglewise.ai/threats/cve-2026-18614-gl-inet-gl-mt3000-command-injection-in-s2s-so"},{"cve":"CVE-2026-12187","cvss":8.8,"slug":"cve-2026-12187-gl-inet-gl-mt3000-command-injection-in-online-firmware-upgrade","title":"GL.iNet GL-MT3000 command injection in Online Firmware Upgrade Handler","severity":"high","exploited":false,"published_at":"2026-06-14T23:16:34.853+00:00","url":"https://junglewise.ai/threats/cve-2026-12187-gl-inet-gl-mt3000-command-injection-in-online-firmware-upgrade"},{"cve":"CVE-2026-12186","cvss":8.8,"slug":"cve-2026-12186-gl-inet-gl-mt3000-command-injection-in-tor-proxy-service","title":"GL.iNet GL-MT3000 command injection in Tor Proxy Service Configuration Handler","severity":"high","exploited":false,"published_at":"2026-06-14T21:16:18.483+00:00","url":"https://junglewise.ai/threats/cve-2026-12186-gl-inet-gl-mt3000-command-injection-in-tor-proxy-service"},{"cve":"CVE-2026-11505","cvss":5,"slug":"cve-2026-11505-gl-inet-routers-hard-coded-authentication-token-in-glnassys","title":"GL.iNet Routers hard-coded authentication token in glnassys","severity":"medium","exploited":false,"published_at":"2026-06-08T12:16:30.747+00:00","url":"https://junglewise.ai/threats/cve-2026-11505-gl-inet-routers-hard-coded-authentication-token-in-glnassys"},{"cve":"CVE-2026-11452","cvss":7.3,"slug":"cve-2026-11452-gl-inet-gl-mt3000-command-injection-in-set-user-pwd-handler","title":"GL.iNet GL-MT3000 command injection in SET_USER_PWD handler","severity":"high","exploited":false,"published_at":"2026-06-07T04:16:29.96+00:00","url":"https://junglewise.ai/threats/cve-2026-11452-gl-inet-gl-mt3000-command-injection-in-set-user-pwd-handler"},{"cve":"CVE-2026-11451","cvss":7.3,"slug":"cve-2026-11451-gl-inet-gl-mt3000-command-injection-in-ftp-protocol-handler","title":"GL.iNet GL-MT3000 command injection in FTP Protocol Handler","severity":"high","exploited":false,"published_at":"2026-06-07T04:16:29.57+00:00","url":"https://junglewise.ai/threats/cve-2026-11451-gl-inet-gl-mt3000-command-injection-in-ftp-protocol-handler"},{"cve":"CVE-2026-11450","cvss":7.3,"slug":"cve-2026-11450-gl-inet-gl-mt3000-command-injection-in-nas-web-so-via-cgi-bin-glc","title":"GL.iNet GL-MT3000 command injection in nas-web.so via /cgi-bin/glc","severity":"high","exploited":false,"published_at":"2026-06-07T03:16:27.247+00:00","url":"https://junglewise.ai/threats/cve-2026-11450-gl-inet-gl-mt3000-command-injection-in-nas-web-so-via-cgi-bin-glc"},{"cve":"CVE-2026-11449","cvss":6.3,"slug":"cve-2026-11449-gl-inet-gl-mt3000-command-injection-in-luci-json-rpc-interface","title":"GL.iNet GL-MT3000 command injection in LuCI JSON-RPC interface","severity":"medium","exploited":false,"published_at":"2026-06-07T03:16:27.077+00:00","url":"https://junglewise.ai/threats/cve-2026-11449-gl-inet-gl-mt3000-command-injection-in-luci-json-rpc-interface"},{"cve":"CVE-2026-11448","cvss":4.7,"slug":"cve-2026-11448-gl-inet-gl-mt3000-command-injection-in-minidlna-service","title":"GL.iNet GL-MT3000 command injection in MiniDLNA Service","severity":"medium","exploited":false,"published_at":"2026-06-07T03:16:26.233+00:00","url":"https://junglewise.ai/threats/cve-2026-11448-gl-inet-gl-mt3000-command-injection-in-minidlna-service"},{"cve":"CVE-2026-11447","cvss":6.3,"slug":"cve-2026-11447-gl-inet-gl-mt3000-command-injection-in-mtk-backend","title":"GL.iNet GL-MT3000 command injection in MTK Backend","severity":"medium","exploited":false,"published_at":"2026-06-07T02:16:23.313+00:00","url":"https://junglewise.ai/threats/cve-2026-11447-gl-inet-gl-mt3000-command-injection-in-mtk-backend"},{"cve":"CVE-2026-11406","cvss":6.3,"slug":"cve-2026-11406-gl-inet-mt3000-command-injection-in-openvpn-client-import","title":"GL.iNet MT3000 command injection in OpenVPN Client Import Workflow","severity":"medium","exploited":false,"published_at":"2026-06-06T10:16:27.017+00:00","url":"https://junglewise.ai/threats/cve-2026-11406-gl-inet-mt3000-command-injection-in-openvpn-client-import"}],"vendor":{"hub":true,"name":"GL.iNet","slug":"gl-inet","homepage":"https://www.gl-inet.com/","description":"A developer of reliable networking devices including travel routers, gateway modules, and IoT solutions.","url":"https://junglewise.ai/threats/vendors/gl-inet"},"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":3,"exploited":0,"vulnerabilities":4},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-18616","cvss":9.8,"epss":0.0362,"slug":"cve-2026-18616-gl-inet-gl-mt3000-command-injection-in-wg-server","title":"GL-iNet GL-MT3000 command injection in wg-server","severity":"critical","exploited":false,"published_at":"2026-08-03T19:16:45.557+00:00","url":"https://junglewise.ai/threats/cve-2026-18616-gl-inet-gl-mt3000-command-injection-in-wg-server"},{"cve":"CVE-2026-18615","cvss":9.8,"epss":0.0362,"slug":"cve-2026-18615-gl-inet-gl-mt3000-command-injection-in-wg-server","title":"GL-iNet GL-MT3000 command injection in wg-server","severity":"critical","exploited":false,"published_at":"2026-08-03T19:16:45.383+00:00","url":"https://junglewise.ai/threats/cve-2026-18615-gl-inet-gl-mt3000-command-injection-in-wg-server"},{"cve":"CVE-2026-18614","cvss":9.8,"epss":0.0362,"slug":"cve-2026-18614-gl-inet-gl-mt3000-command-injection-in-s2s-so","title":"GL-iNet GL-MT3000 command injection in s2s.so","severity":"critical","exploited":false,"published_at":"2026-08-03T19:16:45.2+00:00","url":"https://junglewise.ai/threats/cve-2026-18614-gl-inet-gl-mt3000-command-injection-in-s2s-so"},{"cve":"CVE-2026-18787","cvss":8.8,"epss":0.0321,"slug":"cve-2026-18787-gl-inet-ax1800-command-injection-in-rpc-endpoint","title":"GL.iNet AX1800 command injection in RPC endpoint","severity":"high","exploited":false,"published_at":"2026-08-04T17:16:48.817+00:00","url":"https://junglewise.ai/threats/cve-2026-18787-gl-inet-ax1800-command-injection-in-rpc-endpoint"},{"cve":"CVE-2026-12187","cvss":8.8,"slug":"cve-2026-12187-gl-inet-gl-mt3000-command-injection-in-online-firmware-upgrade","title":"GL.iNet GL-MT3000 command injection in Online Firmware Upgrade Handler","severity":"high","exploited":false,"published_at":"2026-06-14T23:16:34.853+00:00","url":"https://junglewise.ai/threats/cve-2026-12187-gl-inet-gl-mt3000-command-injection-in-online-firmware-upgrade"},{"cve":"CVE-2026-12186","cvss":8.8,"slug":"cve-2026-12186-gl-inet-gl-mt3000-command-injection-in-tor-proxy-service","title":"GL.iNet GL-MT3000 command injection in Tor Proxy Service Configuration Handler","severity":"high","exploited":false,"published_at":"2026-06-14T21:16:18.483+00:00","url":"https://junglewise.ai/threats/cve-2026-12186-gl-inet-gl-mt3000-command-injection-in-tor-proxy-service"},{"cve":"CVE-2026-19983","cvss":8.3,"epss":0.0206,"slug":"cve-2026-19983-gl-inet-multiple-routers-os-command-injection-in-nas-service","title":"GL.iNet multiple routers OS command injection in NAS service","severity":"high","exploited":false,"published_at":"2026-08-17T05:17:09.947+00:00","url":"https://junglewise.ai/threats/cve-2026-19983-gl-inet-multiple-routers-os-command-injection-in-nas-service"},{"cve":"CVE-2026-19979","cvss":8.3,"epss":0.0054,"slug":"cve-2026-19979-gl-inet-webdav-authorization-bypass-in-copy-move","title":"GL.iNet WebDAV authorization bypass in COPY/MOVE","severity":"high","exploited":false,"published_at":"2026-08-17T04:16:55.693+00:00","url":"https://junglewise.ai/threats/cve-2026-19979-gl-inet-webdav-authorization-bypass-in-copy-move"},{"cve":"CVE-2026-19982","cvss":7.4,"epss":0.0177,"slug":"cve-2026-19982-gl-inet-be9300-and-mt6000-os-command-injection-in-firewall","title":"GL.iNet BE9300 and MT6000 OS command injection in firewall-management RPC","severity":"high","exploited":false,"published_at":"2026-08-17T05:17:09.767+00:00","url":"https://junglewise.ai/threats/cve-2026-19982-gl-inet-be9300-and-mt6000-os-command-injection-in-firewall"},{"cve":"CVE-2026-19981","cvss":7.4,"epss":0.0177,"slug":"cve-2026-19981-gl-inet-router-os-command-injection-in-wi-fi-timer-power-schedule","title":"GL.iNet Router OS command injection in Wi-Fi Timer Power-Schedule","severity":"high","exploited":false,"published_at":"2026-08-17T04:16:56.6+00:00","url":"https://junglewise.ai/threats/cve-2026-19981-gl-inet-router-os-command-injection-in-wi-fi-timer-power-schedule"}],"generated_at":"2026-09-28T03:07:00.154823+00:00","technologies":[{"name":"GL.iNet GL-MT3000","slug":"gl-mt3000","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/gl-mt3000"},{"name":"GL.iNet AX1800 (Flint)","slug":"ax1800","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/ax1800"},{"name":"GL.iNet MT3000 (Beryl AX)","slug":"mt3000","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/mt3000"},{"name":"GL.iNet MT6000 (Flint 2)","slug":"mt6000","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/mt6000"},{"name":"GL.iNet A1300 (Slate Plus)","slug":"a1300","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/a1300"},{"name":"GL.iNet AXT1800 (Slate AX)","slug":"axt1800","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/axt1800"},{"name":"GL.iNet MT2500 (Brume 2)","slug":"mt2500","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/mt2500"},{"name":"GL.iNet X3000 (Spitz AX)","slug":"x3000","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/x3000"},{"name":"GL.iNet XE3000 (Puli AX)","slug":"xe3000","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/xe3000"},{"name":"GL.iNet BE10000","slug":"be10000","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/be10000"},{"name":"GL.iNet BE1400","slug":"be1400","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/be1400"},{"name":"GL.iNet BE3600","slug":"be3600","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/be3600"},{"name":"GL.iNet E5800","slug":"e5800","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/e5800"},{"name":"GL.iNet MT3600BE","slug":"mt3600be","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/mt3600be"},{"name":"GL.iNet MT5000","slug":"mt5000","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/mt5000"},{"name":"GL.iNet X2000","slug":"x2000","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/x2000"}]}