Description
A security vulnerability has been detected in GL.iNet BE9300 and MT6000 4.8.x. This vulnerability affects unknown code of the component Firewall-management RPC. The manipulation of the argument dest_port/dest_ip leads to os command injection. The attack may be initiated remotely. Upgrading to version 4.9.0 is able to resolve this issue. The affected component should be upgraded. The vendor explains: "After our investigation, we have confirmed that the vulnerability described (...) does indeed exist."
Published: 2026-08-17
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw exists in the Firewall‑management RPC component of GL.iNet BE9300 and MT6000 routers running firmware 4.8.x. An attacker can supply a crafted dest_port or dest_ip argument that bypasses normal validation and causes the operating system to execute arbitrary shell commands. This permits full control of the device, including data exfiltration, configuration changes, and lateral movement within the network. The weakness corresponds to command injection (CWE‑78) and path traversal (CWE‑77).

Affected Systems

GL.iNet BE9300 and GL.iNet MT6000 routers with firmware version 4.8.x are affected. The vulnerability is resolved in firmware 4.9.0. No other model versions are listed as affected, and no confirmation exists for them.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate severity, and the attack vector is remote, as the RPC interface is reachable over the network. EPSS information is unavailable, so the current likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog, implying no documented widespread exploitation. Nevertheless, because the flaw enables arbitrary command execution, it should be treated as critical.

Generated by OpenCVE AI on August 17, 2026 at 05:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply firmware update 4.9.0 to all affected GL.iNet BE9300 and MT6000 routers.
  • Disable or restrict the Firewall‑management RPC interface to trusted local networks or specific IP ranges.
  • Set up monitoring to detect anomalous command execution or unexpected changes to firewall rules.

Generated by OpenCVE AI on August 17, 2026 at 05:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Gl-inet
Gl-inet be9300
Gl-inet mt6000
Vendors & Products Gl-inet
Gl-inet be9300
Gl-inet mt6000

Mon, 17 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in GL.iNet BE9300 and MT6000 4.8.x. This vulnerability affects unknown code of the component Firewall-management RPC. The manipulation of the argument dest_port/dest_ip leads to os command injection. The attack may be initiated remotely. Upgrading to version 4.9.0 is able to resolve this issue. The affected component should be upgraded. The vendor explains: "After our investigation, we have confirmed that the vulnerability described (...) does indeed exist."
Title GL.iNet BE9300/MT6000 Firewall-management RPC os command injection
First Time appeared Gl.inet
Gl.inet be9300
Gl.inet mt6000
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:gl.inet:be9300:*:*:*:*:*:*:*:*
cpe:2.3:a:gl.inet:mt6000:*:*:*:*:*:*:*:*
Vendors & Products Gl.inet
Gl.inet be9300
Gl.inet mt6000
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 7.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-17T04:15:08.101Z

Reserved: 2026-08-16T13:38:28.793Z

Link: CVE-2026-19982

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T05:17:09.767

Modified: 2026-08-17T05:17:09.767

Link: CVE-2026-19982

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T05:30:16Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')