在 GL.iNet BE9300 和 MT6000 路由器的 4.8.x 版本中检测到一处安全漏洞。该漏洞影响防火墙管理 RPC 组件中的未知代码。通过操控参数 和 ,可导致操作系统命令注入。此攻击可由远程触发。升级至 4.9.0 版本可解决该问题。建议升级受影响的组件。供应商说明:“经我们调查确认,所描述的漏洞确实存在。”
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-19979 | 8.3 HIGH | GL.iNet XE3000 WebDAV Service MOVE authorization |
| CVE-2026-19983 | 8.3 HIGH | GL.iNet XE3000 NAS Command Service gl_nas_sys os command injection |
| CVE-2026-19980 | 7.4 HIGH | GL.iNet XE3000 Language Update ui.update_langs code injection |
| CVE-2026-19981 | 7.4 HIGH | GL.iNet XE3000 Wi-Fi Timer Power-Schedule Feature os command injection |
No comments yet