Authorization Bypass in GL.iNet WebDAV Service Affects Multiple Router Models
CVE-2026-19979
6.9MEDIUM
What is CVE-2026-19979?
A vulnerability has been identified in the WebDAV Service of various GL.iNet router models, allowing remote attackers to bypass authorization mechanisms through targeted manipulation of the COPY/MOVE function. This flaw affects routers with firmware versions up to 4.8.x, including models such as A1300, AX1800, and XE3000 among others. The vendor has acknowledged the existence of this vulnerability following an investigation.
Affected Version(s)
A1300 4.0
A1300 4.1
A1300 4.2
