CVE-2026-19979Disclosure

LOWCVSS 6.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. Affected by this vulnerability is the function COPY/MOVE of the component WebDAV Service. Such manipulation leads to authorization bypass. It is possible to launch the attack remotely. The vendor explains: "After our investigation, we have confirmed that the vulnerability described (...) does indeed exist."

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-08-17); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-08-16: 1Mentions · 2026-08-17: 4Mentions · 2026-09-16: 1Patch / Workaround · 2026-08-17: 1Technical Details · 2026-08-17: 2Technical Details · 2026-09-16: 108-1608-1709-16
Signal classification2 categories
Disclosure
583.3%
General
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-08-161
Disclosure1
2026-08-174
Disclosure3General1
2026-09-161
Disclosure1
Full discourse6 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-19979 A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X30… https://www.cve.org/CVERecord?id=CVE-2026-19979

    Post summary

    A new CVE (CVE-2026-19979) has been identified affecting a range of GL.iNet devices, with a link to the official CVE record.

    000221.3K
    58.1K followersView on X
  • Offensive360@offensive360
    Disclosure

    GL.iNet WebDAV checks auth on GET and PUT, not on COPY and MOVE. CVE-2026-19979, 17 router models, restricted filesystem paths readable remotely. Our write-up on the missed verbs: https://offensive360.com/zerodays/cve-2026-19979-gl-inet-router-firmware/?utm_source=x&utm_medium=social&utm_campaign=daily&utm_content=20260916 #CVE #VulnerabilityResearch https://t.co/JtyJ19pXRz

    Post summary

    The tweet discloses CVE-2026-19979 with technical details about WebDAV auth bypass on COPY/MOVE verbs affecting 17 GL.iNet router models, linking to a write-up, but does not mention a PoC, exploit tool, patch, or active exploitation.

    0000077
    426 followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    GL.iNet routers (A1300, AX1800, MT3000 and others up to 4.8.x) have CVE-2026-19979 (CVSS 8.3). Review firmware updates if deployed: https://nvd.nist.gov/vuln/detail/CVE-2026-19979 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/oLtFD5QhTk

    Post summary

    GL.iNet routers carry CVE‑2026‑19979 with a CVSS of 8.3; users are advised to check and apply any available firmware updates.

    0000040
    94 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19979 A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X30… https://www.cve.org/CVERecord?id=CVE-2026-19979 ----- Traducción: CVE-2026-19979 Se … https://infoflow.cloud`

    Post summary

    The post announces CVE-2026-19979 affecting GL.iNet devices and links to the official CVE record, but provides no additional technical, exploitation, or mitigation details.

    0000035
    100 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-19979 Authorization Bypass in GL.iNet WebDAV Service COPY/MOVE Function https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-19979

    Post summary

    The entry reports CVE-2026-19979 as an authorization bypass issue in GL.iNet’s WebDAV service, but offers no further exploitation, patching, or poC information.

    00000103
    4.1K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in GL.iNet A1300 and other products (CVE-2026-19979) https://vuldb.com/vuln/391161

    Post summary

    A new critical vulnerability (CVE-2026-19979) has been disclosed affecting GL.iNet A1300 and other products.

    00000113
    2.3K followersView on X

Explore more