CVE-2026-19983Disclosure

LOWCVSS 6.9 · MEDIUM

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This issue affects some unknown processing of the file /usr/bin/gl_nas_sys of the component NAS Command Service. The manipulation results in os command injection. The attack may be launched remotely. Upgrading to version 4.9.0 is capable of addressing this issue. It is suggested to upgrade the affected component. The vendor explains: "After our investigation, we have confirmed that the vulnerability described (...) does indeed exist."

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-08-17: 4Patch / Workaround · 2026-08-17: 1Technical Details · 2026-08-17: 208-17
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVE@CVEnew
    General

    CVE-2026-19983 A vulnerability was detected in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This issue affects some unknown processing of the file… https://www.cve.org/CVERecord?id=CVE-2026-19983

    Post summary

    A CVE-2026-19983 vulnerability was identified in several GL.iNet models, but the post contains only minimal information and no indication of exploitation, patches, or PoC details.

    000011.2K
    58.0K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    CVE-2026-19983 - Critical OS command injection in GL.iNet routers (A1300, AX1800, MT3000, etc.) via NAS service. CVSS 8.3. Remote exploitation possible. Unpatched in 4.8.x - upgrade to 4.9.0 now. #CVE #infosec #GLiNet https://www.valtersit.com/cve/CVE-2026-19983/ #CVE #infosec #SysAdmin #cybersecurity #Linux #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta #mexico

    Post summary

    The post highlights CVE‑2026‑19983, a critical OS command injection vulnerability in GL.iNet routers, and urges users to upgrade from unpatched 4.8.x to 4.9.0.

    0000068
    1.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19983 A vulnerability was detected in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This issue affects some unknown processing of the file… https://www.cve.org/CVERecord?id=CVE-2026-19983 ----- Traducción: CVE-2026-19983 Se … https://infoflow.cloud`

    Post summary

    A brief announcement of CVE-2026-19983 impacting several GL.iNet devices, with no further exploit, patch, or technical details provided.

    0000025
    100 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-19983 OS Command Injection in GL.iNet Routers 4.8.x via gl_nas_sys https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-19983

    Post summary

    The post announces CVE-2026-19983, revealing an OS command injection flaw in GL.iNet routers; no PoC, exploit code, or patch details are provided.

    00000107
    4.1K followersView on X

Explore more