CVE-2026-19982
7.4GL.iNet · BE9300, MT6000
A command injection vulnerability in GL.iNet firmware allows authenticated attackers to execute arbitrary system commands via the firewall configuration interface.
Executive summary
A high-severity OS command injection vulnerability in GL.iNet firmware allows authenticated attackers to achieve remote code execution.
Vulnerability
This vulnerability involves an OS command injection flaw (CWE-78) triggered by improper input validation within the firewall management functions. Successful exploitation requires the attacker to have low-level authenticated access to the device management interface.
Business impact
The ability for an attacker to execute arbitrary commands on network infrastructure poses a significant risk to organizational security. This vulnerability could lead to full device compromise, lateral movement into internal segments, or the redirection of network traffic. Given the CVSS score of 7.4, this issue is classified as High severity and requires prompt remediation to prevent unauthorized system control.
Remediation
Immediate Action: Update all affected GL.iNet devices to firmware version 4.9.0 or later to apply the necessary security patches.
Proactive Monitoring: Review device access logs for unusual administrative activity or unexpected system calls originating from the firewall configuration module.
Compensating Controls: Restrict access to the device management interface to trusted administrative IP addresses only, and employ a Web Application Firewall or similar network security appliance to inspect traffic for command injection patterns.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The risk posed by this OS command injection vulnerability is substantial, as it allows for complete control over the network appliance. Administrators should prioritize upgrading firmware to version 4.9.0 across all deployed BE9300 and MT6000 units immediately to neutralize this threat.