CVE-2026-19983 PUBLISHED

GL.iNet XE3000 NAS Command Service gl_nas_sys os command injection

Assigner: VulDB
Reserved: 16.08.2026 Published: 17.08.2026 Updated: 17.08.2026

A vulnerability was detected in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This issue affects some unknown processing of the file /usr/bin/gl_nas_sys of the component NAS Command Service. The manipulation results in os command injection. The attack may be launched remotely. Upgrading to version 4.9.0 is capable of addressing this issue. It is suggested to upgrade the affected component. The vendor explains: "After our investigation, we have confirmed that the vulnerability described (...) does indeed exist."

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X
CVSS Score: 6.9

Product Status

Vendor GL.iNet
Product A1300
Versions
  • Version 4.8.* is affected
  • Version 4.9.0 is unaffected
Vendor GL.iNet
Product AX1800
Versions
  • Version 4.8.* is affected
  • Version 4.9.0 is unaffected
Vendor GL.iNet
Product AXT1800
Versions
  • Version 4.8.* is affected
  • Version 4.9.0 is unaffected
Vendor GL.iNet
Product MT2500
Versions
  • Version 4.8.* is affected
  • Version 4.9.0 is unaffected
Vendor GL.iNet
Product MT3000
Versions
  • Version 4.8.* is affected
  • Version 4.9.0 is unaffected
Vendor GL.iNet
Product MT6000
Versions
  • Version 4.8.* is affected
  • Version 4.9.0 is unaffected
Vendor GL.iNet
Product X3000
Versions
  • Version 4.8.* is affected
  • Version 4.9.0 is unaffected
Vendor GL.iNet
Product XE3000
Versions
  • Version 4.8.* is affected
  • Version 4.9.0 is unaffected

Credits

  • GLiNet (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • OS Command Injection CWE
  • Command Injection CWE