CVE-2026-19983
Received
Received - Intake
OS Command Injection in GL.iNet Routers
Vulnerability report for CVE-2026-19983, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-17
Last updated on: 2026-08-17
Assigner: VulDB
Description
Description
A vulnerability was detected in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This issue affects some unknown processing of the file /usr/bin/gl_nas_sys of the component NAS Command Service. The manipulation results in os command injection. The attack may be launched remotely. Upgrading to version 4.9.0 is capable of addressing this issue. It is suggested to upgrade the affected component. The vendor explains: "After our investigation, we have confirmed that the vulnerability described (...) does indeed exist."
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| gl.inet | a1300 | 4.8.x |
| gl.inet | ax1800 | 4.8.x |
| gl.inet | axt1800 | 4.8.x |
| gl.inet | mt2500 | 4.8.x |
| gl.inet | mt3000 | 4.8.x |
| gl.inet | mt6000 | 4.8.x |
| gl.inet | x3000 | 4.8.x |
| gl.inet | xe3000 | 4.8.x |
| gl.inet | a1300 | 4.9.0 |
| gl.inet | ax1800 | 4.9.0 |
| gl.inet | axt1800 | 4.9.0 |
| gl.inet | mt2500 | 4.9.0 |
| gl.inet | mt3000 | 4.9.0 |
| gl.inet | mt6000 | 4.9.0 |
| gl.inet | x3000 | 4.9.0 |
| gl.inet | xe3000 | 4.9.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-77 | The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component. |
| CWE-78 | The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component. |