CVE-2026-19980

7.4

GL.iNet · A1300, AX1800, AXT1800, BE1400, BE3600, BE6500

A code injection vulnerability in GL.iNet firmware allows authenticated attackers to execute arbitrary code via the language auto-update cron functionality.

Executive summary

A high-severity code injection vulnerability in various GL.iNet routers allows authenticated attackers to gain unauthorized code execution via the auto-update mechanism.

Vulnerability

This vulnerability is a code injection flaw (CWE-94) found within the language auto-update cron process. An attacker with authenticated access can inject malicious commands into the update process, which are then executed by the system.

Business impact

Exploitation of this vulnerability allows an attacker to execute arbitrary code, which can be leveraged to maintain persistence on the device or exfiltrate sensitive configuration data. The CVSS score of 7.4 reflects the high severity of this issue, as it directly impacts the confidentiality, integrity, and availability of the affected network infrastructure.

Remediation

Immediate Action: Monitor official GL.iNet security advisories and apply firmware updates as soon as they are released for your specific model.

Proactive Monitoring: Review system logs for unusual cron job activity or unexpected processes initiated by the language update service.

Compensating Controls: Disable unnecessary management services and ensure that the administrative interface is not exposed to the public internet.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Administrators should treat this vulnerability with high urgency. Because it affects multiple models within the GL.iNet ecosystem, a coordinated update strategy is recommended. Ensure that all devices are running the latest firmware to mitigate risks associated with code injection.

More GL.iNet CVEs