What is CVE-2026-19982?
This vulnerability in GL.iNet BE9300 and MT6000 4.8.x routers allows remote OS command injection via the `dest_port`/`dest_ip` arguments in the Firewall-management RPC component. An attacker can exploit this flaw to execute arbitrary commands on the device. Users are strongly advised to upgrade to a patched version immediately.
Azərbaycanca: GL.iNet BE9300 və MT6000 4.8.x cihazlarında Firewall-management RPC komponentində aşkarlanmış bu boşluq, `dest_port`/`dest_ip` arqumentləri vasitəsilə əməliyyat sistemi əmri inyeksiyasına imkan verir. Zərərli şəxs bu zəiflikdən uzaqdan istifadə edərək cihazda özbaşına əmrlər icra edə bilər. İstifadəçilərə dərhal proqram təminatını təhlükəsiz versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78; shared vendor: GL.iNet
FAQ2
Which component is affected by the CVE-2026-19982 vulnerability in GL.iNet BE9300 and MT6000 devices?
This vulnerability affects the Firewall-management RPC component in GL.iNet BE9300 and MT6000 routers running version 4.8.x.
What can an attacker achieve by exploiting CVE-2026-19982?
An attacker can execute arbitrary commands on the device remotely by performing OS command injection through the `dest_port`/`dest_ip` arguments.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.