CVE-2026-19980

MEDIUM CVSS 4.0: 5.3 EPSS 0.23%
Updated Aug 20, 2026
Gl.Inet
Parameter Value
CVSS 5.3 (MEDIUM)
Type CWE-74 (Injection), CWE-94 (Code Injection)
Vendor Gl.Inet
Public PoC No

A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. Affected by this issue is the function ui.update_langs of the component Language Update. Performing a manipulation of the argument hour/min/week results in code injection.

The attack can be initiated remotely. The vendor explains: "After our investigation, we have confirmed that the vulnerability described (...) does indeed exist."

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
Low
Partial disruption

CVSS Vector v4.0

Vulnerable Products

gl.inet:axt1800 gl.inet:x2000 gl.inet:mt3600be gl.inet:be1400 gl.inet:be10000 gl.inet:be9300 gl.inet:be3600 gl.inet:e5800 gl.inet:xe3000 gl.inet:mt6000 gl.inet:x3000 gl.inet:a1300 gl.inet:mt3000 gl.inet:mt5000 gl.inet:mt2500 gl.inet:ax1800 gl.inet:be6500