在 GL.iNet A1300、AX1800、AXT1800、MT2500、MT3000、MT6000、X3000 和 XE3000 路由器的 4.8.x 版本中发现了一个安全漏洞。该问题影响 NAS 命令服务(NAS Command Service)组件中对文件 的某些未明确处理的操作,可能导致操作系统命令注入(OS Command Injection)。攻击者可通过远程方式利用此漏洞。建议将受影响组件升级至 4.9.0 版本以修复该问题。厂商表示:“经调查,我们确认……所述的漏洞确实存在。”
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GL.iNet | A1300 | 4.8.* |
affected |
4.9.0 |
unaffected | ||
| GL.iNet | AX1800 | 4.8.* |
affected |
4.9.0 |
unaffected | ||
| GL.iNet | AXT1800 | 4.8.* |
affected |
4.9.0 |
unaffected | ||
| GL.iNet | MT2500 | 4.8.* |
affected |
4.9.0 |
unaffected | ||
| GL.iNet | MT3000 | 4.8.* |
affected |
4.9.0 |
unaffected | ||
| GL.iNet | MT6000 | 4.8.* |
affected |
4.9.0 |
unaffected | ||
| GL.iNet | X3000 | 4.8.* |
affected |
4.9.0 |
unaffected | ||
| GL.iNet | XE3000 | 4.8.* |
affected |
4.9.0 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GL.iNet | A1300 | 4.8.* |
cpe:2.3:a:gl.inet:a1300:*:*:*:*:*:*:*:*
|
|
| GL.iNet | AX1800 | 4.8.* |
cpe:2.3:a:gl.inet:ax1800:*:*:*:*:*:*:*:*
|
|
| GL.iNet | AXT1800 | 4.8.* |
cpe:2.3:a:gl.inet:axt1800:*:*:*:*:*:*:*:*
|
|
| GL.iNet | MT2500 | 4.8.* |
cpe:2.3:a:gl.inet:mt2500:*:*:*:*:*:*:*:*
|
|
| GL.iNet | MT3000 | 4.8.* |
cpe:2.3:a:gl.inet:mt3000:*:*:*:*:*:*:*:*
|
|
| GL.iNet | MT6000 | 4.8.* |
cpe:2.3:a:gl.inet:mt6000:*:*:*:*:*:*:*:*
|
|
| GL.iNet | X3000 | 4.8.* |
cpe:2.3:a:gl.inet:x3000:*:*:*:*:*:*:*:*
|
|
| GL.iNet | XE3000 | 4.8.* |
cpe:2.3:a:gl.inet:xe3000:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-19979 | 8.3 HIGH | GL.iNet XE3000 WebDAV Service MOVE authorization |
| CVE-2026-19980 | 7.4 HIGH | GL.iNet XE3000 Language Update ui.update_langs code injection |
| CVE-2026-19981 | 7.4 HIGH | GL.iNet XE3000 Wi-Fi Timer Power-Schedule Feature os command injection |
| CVE-2026-19982 | 7.4 HIGH | GL.iNet BE9300/MT6000 Firewall-management RPC os command injection |
No comments yet