Gl.Inet · X3000 · CVE-2026-19980
**Name of the Vulnerable Software and Affected Versions**
GL.iNet A1300 versions prior to 4.9
GL.iNet AX1800 versions prior to 4.9
GL.iNet AXT1800 versions prior to 4.9
GL.iNet BE1400 versions prior to 4.9
GL.iNet BE3600 versions prior to 4.9
GL.iNet BE6500 versions prior to 4.9
GL.iNet BE9300 versions prior to 4.9
GL.iNet BE10000 versions prior to 4.9
GL.iNet E5800 versions prior to 4.9
GL.iNet MT2500 versions prior to 4.9
GL.iNet MT3000 versions prior to 4.9
GL.iNet MT3600BE versions prior to 4.9
GL.iNet MT5000 versions prior to 4.9
GL.iNet MT6000 versions prior to 4.9
GL.iNet X2000 versions prior to 4.9
GL.iNet X3000 versions prior to 4.9
GL.iNet XE3000 versions prior to 4.9
**Description**
A remote code injection flaw exists within the Language Update component. The issue occurs in the `ui.update langs()` function when the `hour`, `min`, or `week` arguments are manipulated, allowing an attacker to execute arbitrary code remotely.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the `ui.update langs()` function to minimize the risk of exploitation.