Description
A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. Affected by this vulnerability is the function COPY/MOVE of the component WebDAV Service. Such manipulation leads to authorization bypass. It is possible to launch the attack remotely. The vendor explains: "After our investigation, we have confirmed that the vulnerability described (...) does indeed exist."
Published: 2026-08-17
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the WebDAV component’s COPY and MOVE functions allows an attacker to bypass authorization controls, enabling unauthorized manipulation of files on the device. The vulnerability can be exploited remotely through specially crafted WebDAV requests. Although the vendor does not detail the full extent of the impact, the ability to move or copy files without proper authentication could lead to disclosure or alteration of sensitive configuration and firmware data.

Affected Systems

All GL.iNet routers listed in the CNA vendor/product table—namely the A1300, AX1800, AXT1800, BE10000, BE1400, BE3600, BE6500, BE9300, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000, and XE3000—are potentially vulnerable on firmware versions up to 4.8.x. Exact version boundaries are not specified beyond the 4.8.x ceiling.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity, while the EPSS is unavailable, implying unknown exploitation likelihood. The vulnerability is not listed in CISA's KEV catalog. Because the flaw is exploitable remotely via HTTP requests directed at the WebDAV service, an attacker only needs network access to the device, with no local privileges required. Successful exploitation would give the actor the ability to read, modify, or delete arbitrary files through the MOVE and COPY operations, potentially compromising device configuration and integrity.

Generated by OpenCVE AI on August 17, 2026 at 04:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest firmware release from GL.iNet that addresses the WebDAV authorization bypass.
  • If the WebDAV service is not needed for your setup, disable it or enforce strict authentication and access control to the service.
  • Use the router’s firewall or ACLs to block or restrict MOVE and COPY methods from untrusted IP ranges, allowing only trusted management hosts.
  • Keep an eye on system logs for abnormal WebDAV activity and verify that unauthorized file operations do not occur.

Generated by OpenCVE AI on August 17, 2026 at 04:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. Affected by this vulnerability is the function COPY/MOVE of the component WebDAV Service. Such manipulation leads to authorization bypass. It is possible to launch the attack remotely. The vendor explains: "After our investigation, we have confirmed that the vulnerability described (...) does indeed exist."
Title GL.iNet XE3000 WebDAV Service MOVE authorization
First Time appeared Gl.inet
Gl.inet a1300
Gl.inet ax1800
Gl.inet axt1800
Gl.inet be10000
Gl.inet be1400
Gl.inet be3600
Gl.inet be6500
Gl.inet be9300
Gl.inet e5800
Gl.inet mt2500
Gl.inet mt3000
Gl.inet mt3600be
Gl.inet mt5000
Gl.inet mt6000
Gl.inet x2000
Gl.inet x3000
Gl.inet xe3000
Weaknesses CWE-285
CWE-639
CPEs cpe:2.3:a:gl.inet:a1300:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:ax1800:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:axt1800:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:be10000:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:be1400:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:be3600:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:be6500:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:be9300:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:e5800:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:mt2500:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:mt3000:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:mt3600be:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:mt5000:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:mt6000:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:x2000:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:x3000:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:xe3000:*:*:*:*:*:*:*:*
Vendors & Products Gl.inet
Gl.inet a1300
Gl.inet ax1800
Gl.inet axt1800
Gl.inet be10000
Gl.inet be1400
Gl.inet be3600
Gl.inet be6500
Gl.inet be9300
Gl.inet e5800
Gl.inet mt2500
Gl.inet mt3000
Gl.inet mt3600be
Gl.inet mt5000
Gl.inet mt6000
Gl.inet x2000
Gl.inet x3000
Gl.inet xe3000
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-17T03:30:09.125Z

Reserved: 2026-08-16T13:38:11.037Z

Link: CVE-2026-19979

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T04:16:55.693

Modified: 2026-08-17T04:16:55.693

Link: CVE-2026-19979

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T04:30:03Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-639

    Authorization Bypass Through User-Controlled Key