Sceawere
Vulnerability Detail
CVE-2026-19981UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
GL.iNet Wi-Fi Timer OS Command Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.4
- Creation Date
- 3h ago
- Vendor
- GL.iNet
- Product
- A1300
- Attack Type
- OS Command Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. This affects an unknown part of the component Wi-Fi Timer Power-Schedule Feature. Executing a manipulation of the argument switch_power/restore_power can lead to os command injection. The attack can be launched remotely. The vendor explains: "After our investigation, we have confirmed that the vulnerability described (...) does indeed exist."
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.4",
"pubDate": "2026-08-17T04:16:56.600Z",
"pubdate": "2026-08-17T04:16:56.600Z",
"executiveSummary": "A critical OS command injection vulnerability has been identified within multiple GL.iNet router models, specifically affecting the Wi-Fi Timer Power-Schedule Feature up to version 4.8.x. The flaw resides in the handling of the switch_power and restore_power arguments, which fail to properly sanitize user-supplied input before passing it to the underlying operating system shell.\nSuccessful exploitation of this vulnerability allows remote attackers to execute arbitrary OS commands with elevated privileges on the target device. This compromises the entire confidentiality, integrity, and availability of the affected networking hardware. The attack vector is remotely accessible, enabling malicious actors to issue unauthorized commands over the network without requiring physical access.\nImpacted products include GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000, and XE3000 running firmware versions up to 4.8.x. Given the network exposure and potential for complete system compromise, organizations and users utilizing these routers face severe risk implications, including potential network pivoting, traffic interception, and device bricking.\nRemediation requires applying vendor-supplied firmware updates as soon as they become available. Network administrators should restrict management interface exposure to trusted internal networks and disable vulnerable scheduling features if not strictly required.",
"technicalDetails": "The vulnerability is an OS command injection flaw located in the Wi-Fi Timer Power-Schedule Feature of multiple GL.iNet router models running firmware versions up to 4.8.x. The root cause stems from insecure input validation and improper neutralization of special characters within the parameters processed by the backend logic.\nSpecifically, the manipulation of the switch_power and restore_power arguments allows malicious input to be concatenated directly into system-level execution routines or shell invocations. Because the application fails to sanitize or validate these parameters against a strict whitelist or escape metacharacters, an attacker can append arbitrary shell commands to the intended administrative operations.\nThe attack flow proceeds as follows: First, the remote attacker identifies the network-exposed endpoint responsible for the Wi-Fi Timer Power-Schedule Feature. Second, the attacker crafts a malicious HTTP request or API call containing specially crafted input payloads injected into the vulnerable switch_power or restore_power arguments. Third, the backend application passes these unsanitized arguments directly to the underlying operating system shell for execution.\nUpon successful processing of the payload, the underlying OS executes the attacker's appended commands within the execution context of the web application or service, which often operates with high privileges. This leads to immediate arbitrary code execution on the device.\nThe attack can be launched remotely over the network, depending on the exposure configuration of the router management interfaces. The vulnerability affects an unknown internal component function handling the scheduling logic, but the exposed attack surface directly involves the aforementioned arguments. Post-exploitation impact includes full system compromise, alteration of firewall rules, firmware tampering, establishment of persistent backdoors, and unauthorized access to local network traffic traversing the compromised GL.iNet device."
}