CVE-2026-19981Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. This affects an unknown part of the component Wi-Fi Timer Power-Schedule Feature. Executing a manipulation of the argument switch_power/restore_power can lead to os command injection. The attack can be launched remotely. The vendor explains: "After our investigation, we have confirmed that the vulnerability described (...) does indeed exist."

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-08-17: 4Patch / Workaround · 2026-08-17: 1Technical Details · 2026-08-17: 108-17
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-19981 - OS Command Injection in GL.iNet routers (Wi-Fi Timer feature). Remote attack, CVSS 7.4. Affects many models up to 4.8.x. Unpatched - update immediately. #CVE #GLiNet #infosec https://www.valtersit.com/cve/CVE-2026-19981 #CVE #infosec #SysAdmin #cybersecurity #Linux #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta #mexico

    Post summary

    A new OS Command Injection vulnerability (CVE‑2026‑19981) affecting GL.iNet routers is disclosed with a CVSS of 7.4 and an urgent call to apply patches.

    0000072
    1.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19981 A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X30… https://www.cve.org/CVERecord?id=CVE-2026-19981 ----- Traducción: CVE-2026-19981 Se … https://infoflow.cloud`

    Post summary

    The post announces the discovery of CVE‑2026‑19981 in GL.iNet devices and directs readers to the official CVE record, with no additional exploit or mitigation information.

    0000030
    100 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19981 A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X30… https://www.cve.org/CVERecord?id=CVE-2026-19981

    Post summary

    A weakness has been identified in multiple GL.iNet device models under CVE-2026-19981, but the announcement provides no further technical details or exploitation information.

    000001.2K
    58.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-19981 OS Command Injection in GL.iNet Routers via Wi-Fi Timer Power-Schedule Feature https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-19981

    Post summary

    A brief announcement of a CVE involving OS command injection in GL.iNet routers, with no further details, PoC, or mitigation information provided.

    0000093
    4.1K followersView on X

Explore more