CVE-2026-19979
8.3GL.iNet · A1300, AX1800, AXT1800, BE1400, BE3600, BE6500
Multiple GL.iNet router models are susceptible to an authorization bypass vulnerability in the WebDAV public-share feature, allowing unauthenticated access to shared resources.
Executive summary
An authorization bypass vulnerability in GL.iNet routers allows unauthenticated attackers to access restricted WebDAV public shares, posing a significant risk of unauthorized data exposure.
Vulnerability
The vulnerability involves an improper authorization mechanism within the WebDAV public-share function (CWE-639, CWE-285). This flaw permits unauthenticated network-adjacent or remote attackers to bypass access controls and interact with shared data.
Business impact
The ability for an unauthenticated user to bypass authorization controls on a network device represents a significant breach of confidentiality and integrity. Given the CVSS score of 8.3, this high-severity vulnerability could lead to the unauthorized retrieval of sensitive files stored on connected storage media or the injection of malicious content into shared directories. Such exposure may result in data loss, regulatory non-compliance, and potential compromise of internal network information.
Remediation
Immediate Action: Disable the WebDAV public-share feature on all affected GL.iNet devices until a security patch is released by the vendor.
Proactive Monitoring: Review system and WebDAV access logs for unauthorized file access attempts or anomalous traffic patterns originating from unknown IP addresses.
Compensating Controls: Implement network-level access control lists or a firewall to restrict access to the WebDAV service to known, trusted internal IP addresses only.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the severity of this authorization bypass, administrators must prioritize the immediate disabling of the vulnerable WebDAV feature. Users should monitor official GL.iNet firmware update channels closely and apply the forthcoming patch as soon as it is made available to fully remediate the underlying logic error.