Code Injection Vulnerability in GL.iNet Routers and Products
CVE-2026-19980
5.3MEDIUM
What is CVE-2026-19980?
A security vulnerability has been identified in various GL.iNet router models related to the function ui.update_langs in the Language Update component. This flaw allows for a remote code injection attack by manipulating the hour/min/week parameters, potentially compromising the device. The vendor has acknowledged the existence of this vulnerability following an internal investigation.
Affected Version(s)
A1300 4.0
A1300 4.1
A1300 4.2
