CVE-2026-19981
Received
Received - Intake
OS Command Injection in GL.iNet Routers via Wi-Fi Timer Feature
Vulnerability report for CVE-2026-19981, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-17
Last updated on: 2026-08-17
Assigner: VulDB
Description
Description
A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. This affects an unknown part of the component Wi-Fi Timer Power-Schedule Feature. Executing a manipulation of the argument switch_power/restore_power can lead to os command injection. The attack can be launched remotely. The vendor explains: "After our investigation, we have confirmed that the vulnerability described (...) does indeed exist."
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| gl.inet | a1300 | * |
| gl.inet | ax1800 | * |
| gl.inet | axt1800 | * |
| gl.inet | be1400 | * |
| gl.inet | be3600 | * |
| gl.inet | be6500 | * |
| gl.inet | be9300 | * |
| gl.inet | be10000 | * |
| gl.inet | e5800 | * |
| gl.inet | mt2500 | * |
| gl.inet | mt3000 | * |
| gl.inet | mt3600be | * |
| gl.inet | mt5000 | * |
| gl.inet | mt6000 | * |
| gl.inet | x2000 | * |
| gl.inet | x3000 | * |
| gl.inet | xe3000 | to 4.8.x (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-77 | The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component. |
| CWE-78 | The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component. |