PT-2026-73201 · Gl.Inet · Be9300+1

·

CVE-2026-19982

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions GL.iNet BE9300 versions 4.8.x GL.iNet MT6000 versions 4.8.x
Description An OS command injection flaw exists in the Firewall-management RPC component. A remote attacker can exploit this by manipulating the dest port and dest ip arguments, allowing for the execution of arbitrary operating system commands.
Recommendations Upgrade GL.iNet BE9300 to version 4.9.0. Upgrade GL.iNet MT6000 to version 4.9.0.

Exploit

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19982

Affected Products

Be9300
Mt6000