SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-19981

HIGH · CVSS 7.4 EPSS 1.05% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

A command injection vulnerability exists in the Wi-Fi Timer Power-Schedule Feature of multiple GL.iNet router models running versions up to 4.8.x, allowing remote attackers to execute arbitrary operating system commands. This high-severity flaw poses a significant risk to network integrity and confidentiality, making it critical for organizations using these devices to prioritize patching. Network administrators and security teams should take immediate action to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19981
Severity
HIGH
CVSS
7.4
EPSS
1.05%

Original NVD Description

A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. This affects an unknown part of the component Wi-Fi Timer Power-Schedule Feature. Executing a manipulation of the argument switch_power/restore_power can lead to os command injection. The attack can be launched remotely. The vendor explains: "After our investigation, we have confirmed that the vulnerability described (...) does indeed exist."