Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 17 Aug 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gl-inet
Gl-inet a1300 Gl-inet ax1800 Gl-inet axt1800 Gl-inet mt2500 Gl-inet mt3000 Gl-inet mt6000 Gl-inet x3000 Gl-inet xe3000 |
|
| Vendors & Products |
Gl-inet
Gl-inet a1300 Gl-inet ax1800 Gl-inet axt1800 Gl-inet mt2500 Gl-inet mt3000 Gl-inet mt6000 Gl-inet x3000 Gl-inet xe3000 |
Mon, 17 Aug 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This issue affects some unknown processing of the file /usr/bin/gl_nas_sys of the component NAS Command Service. The manipulation results in os command injection. The attack may be launched remotely. Upgrading to version 4.9.0 is capable of addressing this issue. It is suggested to upgrade the affected component. The vendor explains: "After our investigation, we have confirmed that the vulnerability described (...) does indeed exist." | |
| Title | GL.iNet XE3000 NAS Command Service gl_nas_sys os command injection | |
| First Time appeared |
Gl.inet
Gl.inet a1300 Gl.inet ax1800 Gl.inet axt1800 Gl.inet mt2500 Gl.inet mt3000 Gl.inet mt6000 Gl.inet x3000 Gl.inet xe3000 |
|
| Weaknesses | CWE-77 CWE-78 |
|
| CPEs | cpe:2.3:a:gl.inet:a1300:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:ax1800:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:axt1800:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:mt2500:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:mt3000:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:mt6000:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:x3000:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:xe3000:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Gl.inet
Gl.inet a1300 Gl.inet ax1800 Gl.inet axt1800 Gl.inet mt2500 Gl.inet mt3000 Gl.inet mt6000 Gl.inet x3000 Gl.inet xe3000 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Subscriptions
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-17T04:30:11.277Z
Reserved: 2026-08-16T13:38:32.594Z
Link: CVE-2026-19983
No data.
Status : Received
Published: 2026-08-17T05:17:09.947
Modified: 2026-08-17T05:17:09.947
Link: CVE-2026-19983
No data.
OpenCVE Enrichment
Updated: 2026-08-17T07:00:08Z