PT-2026-73202 · Gl.Inet · Mt3000+6

·

CVE-2026-19983

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions GL.iNet A1300 versions 4.8.x GL.iNet AX1800 versions 4.8.x GL.iNet AXT1800 versions 4.8.x GL.iNet MT2500 versions 4.8.x GL.iNet MT3000 versions 4.8.x GL.iNet MT6000 versions 4.8.x GL.iNet X3000 versions 4.8.x GL.iNet XE3000 versions 4.8.x
Description An OS command injection flaw exists in the NAS Command Service component due to improper processing of the /usr/bin/gl nas sys file. This issue allows a remote attacker to execute arbitrary operating system commands.
Recommendations Upgrade GL.iNet A1300 to version 4.9.0. Upgrade GL.iNet AX1800 to version 4.9.0. Upgrade GL.iNet AXT1800 to version 4.9.0. Upgrade GL.iNet MT2500 to version 4.9.0. Upgrade GL.iNet MT3000 to version 4.9.0. Upgrade GL.iNet MT6000 to version 4.9.0. Upgrade GL.iNet X3000 to version 4.9.0. Upgrade GL.iNet XE3000 to version 4.9.0.

Exploit

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19983

Affected Products

A1300
Axt1800
Mt2500
Mt3000
Mt6000
X3000
Xe3000