OS Command Injection Vulnerability in GL.iNet Routers
CVE-2026-19981
5.3MEDIUM
What is CVE-2026-19981?
A security issue has been detected in various GL.iNet router models related to their Wi-Fi Timer Power-Schedule feature. By manipulating the arguments switch_power or restore_power, attackers can execute OS commands, potentially compromising the device. This vulnerability is exploitable remotely and poses a significant risk, emphasizing the need for prompt attention by users of the affected models to ensure their devices are updated and secure.
Affected Version(s)
A1300 4.0
A1300 4.1
A1300 4.2
