PT-2026-73198 · Gl.Inet · Be10000+15

·

CVE-2026-19979

·

Published

2026-08-17

·

Updated

2026-08-18

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions GL.iNet A1300 versions prior to 4.9 GL.iNet AX1800 versions prior to 4.9 GL.iNet AXT1800 versions prior to 4.9 GL.iNet BE1400 versions prior to 4.9 GL.iNet BE3600 versions prior to 4.9 GL.iNet BE6500 versions prior to 4.9 GL.iNet BE9300 versions prior to 4.9 GL.iNet BE10000 versions prior to 4.9 GL.iNet E5800 versions prior to 4.9 GL.iNet MT2500 versions prior to 4.9 GL.iNet MT3000 versions prior to 4.9 GL.iNet MT3600BE versions prior to 4.9 GL.iNet MT5000 versions prior to 4.9 GL.iNet MT6000 versions prior to 4.9 GL.iNet X2000 versions prior to 4.9 GL.iNet X3000 versions prior to 4.9 GL.iNet XE3000 versions prior to 4.9
Description A remote authorization bypass exists within the WebDAV Service component. The issue occurs during the execution of the COPY() and MOVE() functions, allowing an attacker to bypass security restrictions remotely.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the WebDAV Service component to minimize the risk of exploitation.

Exploit

Improper Authorization

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19979

Affected Products

A1300
Axt1800
Be10000
Be1400
Be3600
Be6500
Be9300
E5800
Mt2500
Mt3000
Mt3600Be
Mt5000
Mt6000
X2000
X3000
Xe3000