🚨 GL.iNet Routers Hit by Remote NAS Command Injection
Administrators running affected GL.iNet models on 4.8.x should move to 4.9.0 promptly, especially where NAS functionality is exposed to untrusted networks.
CVE-2026-19983 is an OS command injection vulnerability in the NAS Command Service of multiple GL.iNet router models running 4.8.x. The flaw can be exploited remotely through processing involving /usr/bin/gl_nas_sys. It is rated HIGH with CVSS 8.3, and upgrading to version 4.9.0 addresses the issue.
🔗 Read more 🔗
Source: NVD
⚠️ Public Exploit Targets Edimax WAN Command Injection
EW-7478APC operators should treat this as urgent because exploit code is already public. The entry lists no vendor fix, so restrict management exposure and replace or mitigate affected devices where patching is unavailable.
CVE-2026-19962 is a command injection vulnerability in the setWAN function of Edimax EW-7478APC 1.04. Manipulating username parameters in /goform/setWAN can enable a remote attack. It is rated HIGH with CVSS 7.4, and a public exploit has been published and may be used.
🔗 Read more 🔗
Source: NVD
⚠️ Edimax Access Point Command Injection Exploit Goes Public
Owners of EW-7478APC devices should prioritize mitigation because exploit details are public and the vendor reportedly did not respond. Limit access to the management interface and plan replacement if no fixed firmware is available.
CVE-2026-19963 is a command injection vulnerability in the stainfo function of Edimax EW-7478APC 1.04. Manipulation of the interface argument in /goform/stainfo can be exploited remotely. It is rated HIGH with CVSS 7.4, and the exploit has been publicly disclosed and may be used.
🔗 Read more 🔗
Source: NVD
🔥 Critical ipTIME Authentication Bypass Has Public Exploit
A3004T operators should treat this as an emergency-level issue given the CVSS 10.0 rating, remote reachability, and public exploit. Isolate affected management interfaces immediately and apply a vendor fix if one becomes available.
CVE-2026-19977 is an improper authentication vulnerability in the Session Validation component of EFM ipTIME A3004T 14.19.0. The flaw affects httpcon_check_session_url and can be exploited remotely to bypass authentication. It is rated CRITICAL with CVSS 10.0, and a public exploit is available and may be used.
🔗 Read more 🔗
Source: NVD
🔐 Planet9 File Permissions Enable SYSTEM Privilege Escalation
Organizations with Planet9 installed should patch affected endpoints promptly, particularly shared or multi-user systems. Until a fix is deployed, restrict local access and monitor the service executable for unauthorized modification.
CVE-2026-50602 is a privilege-escalation vulnerability in Planet9 caused by overly permissive permissions on an executable used by a background service. An authenticated local user could modify or replace that executable and gain arbitrary code execution with SYSTEM privileges when the service starts or the machine reboots. It is rated HIGH with CVSS 8.5.
🔗 Read more 🔗
Source: NVD
🛡️ GL.iNet WebDAV Flaw Allows Remote Authorization Bypass
GL.iNet administrators using WebDAV should prioritize affected devices and restrict service exposure until fixed firmware is deployed. Internet-facing or otherwise untrusted access deserves the fastest attention.
CVE-2026-19979 is an authorization bypass affecting the WebDAV Service across numerous GL.iNet routers running up to 4.8.x. The vulnerability is tied to COPY and MOVE functionality and can be attacked remotely. It is rated HIGH with CVSS 8.3, and GL.iNet has confirmed that the vulnerability exists.
🔗 Read more 🔗
Source: NVD
💥 GL.iNet Language Update Feature Exposed to Remote Code Injection
Operators of affected GL.iNet firmware should update as soon as a fixed release is available and keep administrative services off untrusted networks in the meantime. Remote code injection makes exposed devices a priority.
CVE-2026-19980 is a code injection vulnerability affecting the ui.update_langs function in the Language Update component of multiple GL.iNet routers running up to 4.8.x. Manipulating the hour, min, or week arguments can trigger the flaw remotely. It is rated HIGH with CVSS 7.4, and the vendor has confirmed the vulnerability.
🔗 Read more 🔗
Source: NVD
🚨 GL.iNet Wi-Fi Scheduler Vulnerable to Remote OS Command Injection
Affected GL.iNet deployments should be patched when corrected firmware is available, with externally reachable administration interfaces handled first. Restrict access to the vulnerable functionality as an interim measure.
CVE-2026-19981 is an OS command injection vulnerability in the Wi-Fi Timer Power-Schedule feature of numerous GL.iNet routers running up to 4.8.x. Manipulation of the switch_power or restore_power arguments can enable a remote attack. It is rated HIGH with CVSS 7.4, and GL.iNet has confirmed that the flaw exists.
🔗 Read more 🔗
Source: NVD
🔥 GL.iNet Firewall RPC Command Injection Fixed in 4.9.0
BE9300 and MT6000 administrators on 4.8.x should upgrade to 4.9.0 promptly. Because the flaw is remotely reachable and affects firewall-management functionality, exposed devices should be patched first.
CVE-2026-19982 is an OS command injection vulnerability in the Firewall-management RPC component of GL.iNet BE9300 and MT6000 devices running 4.8.x. Manipulating dest_port or dest_ip can allow remote exploitation. It is rated HIGH with CVSS 7.4, and upgrading to version 4.9.0 resolves the issue.
🔗 Read more 🔗
Source: NVD
🔥 Critical Edimax Buffer Overflow Has Public Exploit
EW-7478APC owners should handle this urgently because of the CVSS 9.9 severity and publicly available exploit. With no vendor response noted, isolate management access and consider replacing the device if patched firmware is unavailable.
CVE-2026-19959 is a stack-based buffer overflow in the formWanTcpipSetup function of Edimax EW-7478APC 1.04. Manipulating the pppUserName argument can trigger the vulnerability remotely. It is rated CRITICAL with CVSS 9.9, and a public exploit is available and could be used for attacks.
🔗 Read more 🔗
Source: NVD
⚠️ Public Edimax Exploit Enables Remote Command Injection
Administrators still running EW-7478APC 1.04 should mitigate this quickly because exploit code is public. Restrict access to the affected interface and pursue patched firmware or device replacement given the lack of vendor response reported.
CVE-2026-19960 is a command injection vulnerability in the formWlbasic function of Edimax EW-7478APC 1.04. Manipulation of the rootAPmac argument in /goform/formWlbasic can be exploited remotely. It is rated HIGH with CVSS 7.4, and the exploit has been publicly disclosed and may be used.
🔗 Read more 🔗
Source: NVD
🔥 Critical Edimax Site Survey Buffer Overflow Exploit Is Public
This should be an urgent priority for anyone operating EW-7478APC 1.04 because the vulnerability is remotely exploitable, nearly maximum severity, and has public exploit code. Isolate affected interfaces and replace or patch devices as soon as a remedy is available.
CVE-2026-19961 is a buffer overflow vulnerability in the formWlSiteSurvey function of Edimax EW-7478APC 1.04. Manipulating the selSSID argument in /goform/formWlSiteSurvey can trigger the flaw remotely. It is rated CRITICAL with CVSS 9.9, and a public exploit is available and may be used.
🔗 Read more 🔗
Source: NVD