CVE-2026-19980
Received Received - Intake

Code Injection in GL.iNet Routers via Language Update

Vulnerability report for CVE-2026-19980, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-17

Last updated on: 2026-08-17

Assigner: VulDB

Description

A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. Affected by this issue is the function ui.update_langs of the component Language Update. Performing a manipulation of the argument hour/min/week results in code injection. The attack can be initiated remotely. The vendor explains: "After our investigation, we have confirmed that the vulnerability described (...) does indeed exist."

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-17
Last Modified
2026-08-17
Generated
2026-08-17
AI Q&A
2026-08-17
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 17 associated CPEs
Vendor Product Version / Range
gl.inet a1300 *
gl.inet ax1800 *
gl.inet axt1800 *
gl.inet be1400 *
gl.inet be3600 *
gl.inet be6500 *
gl.inet be9300 *
gl.inet be10000 *
gl.inet e5800 *
gl.inet mt2500 *
gl.inet mt3000 *
gl.inet mt3600be *
gl.inet mt5000 *
gl.inet mt6000 *
gl.inet x2000 *
gl.inet x3000 *
gl.inet xe3000 to 4.8.x (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-19980 is a Remote Code Execution (RCE) flaw in GL.iNet routers affecting the Language Auto-Update Cron feature. The vulnerability exists in the ui.update_langs function which fails to validate numeric inputs for hour, minute, and week fields. This allows attackers to inject arbitrary commands that execute with root privileges when the scheduled task runs.

Detection Guidance

Check if your GL.iNet device is running firmware version 4.6 or later. Inspect the Language Auto-Update Cron feature for unscheduled or suspicious tasks. Look for unexpected changes in system files or configurations. Monitor network traffic for unusual outbound connections from the device.

Impact Analysis

This vulnerability allows attackers to execute arbitrary root commands, modify router configurations, alter network settings (DNS, firewall, Wi-Fi), read sensitive files, install persistent malware, or pivot into connected networks. The impact includes full system compromise and potential network infiltration.

Compliance Impact

This vulnerability allows remote code execution with root privileges, enabling attackers to access, modify, or exfiltrate sensitive data. For GDPR, this could lead to unauthorized data processing or breaches. For HIPAA, it risks exposing protected health information. Non-compliance risks include fines and legal penalties due to inadequate security controls.

Mitigation Strategies

Disable the Language Auto-Update Cron feature immediately. Update to the latest firmware version if available. Restrict remote access to the device's admin interface. Review and remove any unauthorized scheduled tasks or cron jobs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19980. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart