Sceawere

Vulnerability Detail

CVE-2026-19979UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

GL.iNet WebDAV Authorization Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
8.3
Creation Date
3h ago
Vendor
GL.iNet
Product
A1300
Attack Type
Authorization Bypass
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. Affected by this vulnerability is the function COPY/MOVE of the component WebDAV Service. Such manipulation leads to authorization bypass. It is possible to launch the attack remotely. The vendor explains: "After our investigation, we have confirmed that the vulnerability described (...) does indeed exist."

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.3",
  "pubDate": "2026-08-17T04:16:55.693Z",
  "pubdate": "2026-08-17T04:16:55.693Z",
  "executiveSummary": "An authorization bypass vulnerability has been identified within the WebDAV Service component of multiple GL.iNet router models, specifically impacting the COPY/MOVE functions. This security flaw allows remote attackers to manipulate WebDAV operations, leading to unauthorized access and function execution without proper validation. The affected products include GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000, and XE3000 running firmware versions up to 4.8.x. The risk implications are severe, as successful exploitation enables remote adversaries to bypass access controls and potentially manipulate sensitive file structures managed by the WebDAV service. The vendor has officially confirmed the existence of this vulnerability following internal investigations. Exploitation requires network connectivity to the vulnerable WebDAV service interface, permitting remote threat actors to leverage the flaw without interacting with local physical interfaces.",
  "technicalDetails": "The vulnerability resides in the WebDAV Service component of the affected GL.iNet firmware versions up to 4.8.x, specifically centered around the handling of HTTP methods or protocol commands associated with the COPY and MOVE functions. The root cause stems from insufficient authorization checks and inadequate input validation within the request processing logic of these specific functions, permitting unauthorized callers to invoke restricted operations.\nDuring standard operation, WebDAV services utilize HTTP extensions to support resource management, including duplicating or relocating files and directories via COPY and MOVE requests. Due to the authorization bypass flaw, the underlying application logic fails to properly verify whether the session or originating request possesses the requisite privileges or authentication tokens to execute the requested transaction.\nAn attacker can exploit this flaw by constructing specially crafted remote HTTP requests targeting the WebDAV service interface. The attack flow initiates with the adversary transmitting a remote request leveraging the vulnerable COPY or MOVE functions. Because the vulnerable component lacks rigorous access control enforcement during the processing of these specific methods, the application implicitly trusts the request parameters and executes the file manipulation instruction.\nThis behavior results in unauthorized data relocation, potential overwriting of critical system assets, or exposure of restricted directories depending on the exposed filesystem context. The attack vector is fully remote, functioning across network interfaces exposed by the router firmware. Authentication and privilege requirements are effectively bypassed due to the flawed validation logic, allowing unauthenticated or low-privileged remote entities to execute high-privilege file operations. Post-exploitation impact encompasses unauthorized data manipulation, potential information disclosure, and compromise of data integrity within the storage spaces managed by the WebDAV daemon."
}
CVE-2026-19979: GL.iNet WebDAV Authorization Bypass (HIGH Severity, CVSS: 8.3) - Sceawere