Glinet

#4594of 56,328
60.3Total CVSS
Vulnerabilities · 9
Medium
4
High
5
PT-2026-73200
7.4
2026-08-17
Gl.Inet · X3000 · CVE-2026-19981
**Name of the Vulnerable Software and Affected Versions** GL.iNet A1300 versions prior to 4.8.x GL.iNet AX1800 versions prior to 4.8.x GL.iNet AXT1800 versions prior to 4.8.x GL.iNet BE1400 versions prior to 4.8.x GL.iNet BE3600 versions prior to 4.8.x GL.iNet BE6500 versions prior to 4.8.x GL.iNet BE9300 versions prior to 4.8.x GL.iNet BE10000 versions prior to 4.8.x GL.iNet E5800 versions prior to 4.8.x GL.iNet MT2500 versions prior to 4.8.x GL.iNet MT3000 versions prior to 4.8.x GL.iNet MT3600BE versions prior to 4.8.x GL.iNet MT5000 versions prior to 4.8.x GL.iNet MT6000 versions prior to 4.8.x GL.iNet X2000 versions prior to 4.8.x GL.iNet X3000 versions prior to 4.8.x GL.iNet XE3000 versions prior to 4.8.x **Description** A weakness in the Wi-Fi Timer Power-Schedule Feature allows for remote OS command injection. This occurs when the `switch power` or `restore power` arguments are manipulated. **Recommendations** Update GL.iNet A1300 to version 4.8.x or later. Update GL.iNet AX1800 to version 4.8.x or later. Update GL.iNet AXT1800 to version 4.8.x or later. Update GL.iNet BE1400 to version 4.8.x or later. Update GL.iNet BE3600 to version 4.8.x or later. Update GL.iNet BE6500 to version 4.8.x or later. Update GL.iNet BE9300 to version 4.8.x or later. Update GL.iNet BE10000 to version 4.8.x or later. Update GL.iNet E5800 to version 4.8.x or later. Update GL.iNet MT2500 to version 4.8.x or later. Update GL.iNet MT3000 to version 4.8.x or later. Update GL.iNet MT3600BE to version 4.8.x or later. Update GL.iNet MT5000 to version 4.8.x or later. Update GL.iNet MT6000 to version 4.8.x or later. Update GL.iNet X2000 to version 4.8.x or later. Update GL.iNet X3000 to version 4.8.x or later. Update GL.iNet XE3000 to version 4.8.x or later. As a temporary workaround, restrict access to the Wi-Fi Timer Power-Schedule Feature to minimize the risk of exploitation.
PT-2026-67144
4.3
2026-08-03
Gl.Inet · Be9300 · CVE-2026-18585
**Name of the Vulnerable Software and Affected Versions** GL.iNet MT3000 versions prior to 20260707 GL.iNet MT6000 versions prior to 20260707 GL.iNet BE9300 versions prior to 20260707 GL.iNet BE3600 versions prior to 20260707 GL.iNet MT3600BE versions prior to 20260707 GL.iNet E5800 versions prior to 20260707 GL.iNet BE6500 versions prior to 20260707 GL.iNet MT5000 versions prior to 20260707 GL.iNet X3000 versions prior to 20260707 GL.iNet XE3000 versions prior to 20260707 GL.iNet MT2500 versions prior to 20260707 **Description** A remote attack can trigger a heap-based buffer overflow, which occurs when a program writes more data to a heap memory area than it can hold, potentially leading to crashes or arbitrary code execution. This issue exists within the APPS-NAS Module, specifically in the `nas-web.get file list()` function. **Recommendations** Update MT3000 to version 20260707 or later. Update MT6000 to version 20260707 or later. Update BE9300 to version 20260707 or later. Update BE3600 to version 20260707 or later. Update MT3600BE to version 20260707 or later. Update E5800 to version 20260707 or later. Update BE6500 to version 20260707 or later. Update MT5000 to version 20260707 or later. Update X3000 to version 20260707 or later. Update XE3000 to version 20260707 or later. Update MT2500 to version 20260707 or later. As a temporary workaround, restrict access to the `nas-web.get file list()` function within the APPS-NAS Module.