Authorization Bypass in GL.iNet WebDAV Service Affects Multiple Router Models
CVE-2026-19979

6.9MEDIUM

Key Information:

Vendor

Gl.inet

Status
Vendor
CVE Published:
17 August 2026

What is CVE-2026-19979?

A vulnerability has been identified in the WebDAV Service of various GL.iNet router models, allowing remote attackers to bypass authorization mechanisms through targeted manipulation of the COPY/MOVE function. This flaw affects routers with firmware versions up to 4.8.x, including models such as A1300, AX1800, and XE3000 among others. The vendor has acknowledged the existence of this vulnerability following an investigation.

Affected Version(s)

A1300 4.0

A1300 4.1

A1300 4.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

GLiNet (VulDB User)
VulDB CNA Team
.