GL.iNet Routers: Five High-Severity Vulnerabilities Disclosed Together, Patched in 4.9.0
GL.iNet routers affected by five high-severity vulnerabilities, including command injection and authorization bypass, patched in version 4.9.0.

Key findings
- Five high-severity vulnerabilities disclosed together for GL.iNet routers on August 17, 2026.
- Flaws include OS command injection and authorization bypass across multiple services.
- Impacts a wide range of GL.iNet models running firmware up to version 4.8.x.
- Patched in firmware version 4.9.0; users urged to update promptly.
On August 17, 2026, a batch of five high-severity vulnerabilities was disclosed for GL.iNet devices, impacting a wide range of their routers and networking equipment. These vulnerabilities, all disclosed within a one-hour window, collectively expose users to risks including command injection and authorization bypass. The affected devices run firmware versions up to 4.8.x, with updates to version 4.9.0 recommended to mitigate these risks.
Several of the vulnerabilities center on command injection flaws. CVE-2026-19983, affecting models like the A1300 and AX1800, exploits a vulnerability in the NAS Command Service, specifically in the /usr/bin/gl_nas_sys file, allowing for OS command injection. Similarly, CVE-2026-19982 targets the Firewall-management RPC component in models such as the BE9300 and MT6000, enabling remote command injection through manipulation of dest_port and dest_ip arguments.
Other vulnerabilities disclosed in this batch include issues related to authorization and potential system manipulation. CVE-2026-19979, impacting a broad array of GL.iNet devices, involves an authorization bypass vulnerability within the WebDAV Service's COPY/MOVE functionality. Additionally, CVE-2026-19980 affects the Language Update component, specifically the ui.update_langs function, though the exact impact of manipulation here is described as unknown. CVE-2026-19981 points to a weakness in the Wi-Fi Timer Power-Schedule Feature, where manipulation of the switch argument could lead to unspecified adverse effects.
The widespread nature of these vulnerabilities across numerous GL.iNet models, including popular consumer and prosumer devices, underscores the importance of timely patching. The vendor has indicated that upgrading to firmware version 4.9.0 resolves these issues. Users are strongly advised to apply this update to protect their networks from potential remote exploitation. The clustering of these disclosures suggests a coordinated vulnerability discovery and reporting process, highlighting the ongoing need for vigilance in securing Internet of Things (IoT) devices.
This batch of vulnerabilities serves as a reminder for GL.iNet users to maintain up-to-date firmware on their devices. The identified flaws, ranging from command injection to authorization bypass, could allow attackers to gain unauthorized control or disrupt network services. Prompt application of the available security patches is the most effective defense against these threats.
The affected products include GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000, and XE3000. The vulnerabilities were patched in version 4.9.0.
The vulnerabilities disclosed are:
- CVE-2026-19983: OS command injection in NAS Command Service.
- CVE-2026-19982: OS command injection in Firewall-management RPC.
- CVE-2026-19981: Weakness in Wi-Fi Timer Power-Schedule Feature.
- CVE-2026-19980: Flaw in Language Update component's
ui.update_langsfunction. - CVE-2026-19979: Authorization bypass in WebDAV Service.