Analysis and contextual insights are available on OpenCVE Cloud.
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| GL.iNet | A1300 | affected |
|
||||||||||||||||||||||||||||||
| GL.iNet | AX1800 | affected |
|
||||||||||||||||||||||||||||||
| GL.iNet | AXT1800 | affected |
|
||||||||||||||||||||||||||||||
| GL.iNet | BE1400 | affected |
|
||||||||||||||||||||||||||||||
| GL.iNet | BE3600 | affected |
|
||||||||||||||||||||||||||||||
| GL.iNet | BE6500 | affected |
|
||||||||||||||||||||||||||||||
| GL.iNet | BE9300 | affected |
|
||||||||||||||||||||||||||||||
| GL.iNet | BE10000 | affected |
|
||||||||||||||||||||||||||||||
| GL.iNet | E5800 | affected |
|
||||||||||||||||||||||||||||||
| GL.iNet | MT2500 | affected |
|
||||||||||||||||||||||||||||||
| GL.iNet | MT3000 | affected |
|
||||||||||||||||||||||||||||||
| GL.iNet | MT3600BE | affected |
|
||||||||||||||||||||||||||||||
| GL.iNet | MT5000 | affected |
|
||||||||||||||||||||||||||||||
| GL.iNet | MT6000 | affected |
|
||||||||||||||||||||||||||||||
| GL.iNet | X2000 | affected |
|
||||||||||||||||||||||||||||||
| GL.iNet | X3000 | affected |
|
||||||||||||||||||||||||||||||
| GL.iNet | XE3000 | affected |
|
No data.
No data.
No data available yet.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
- CVSS v4.0 5.3 Medium
- CVSS v3.1 7.4 High
- CVSS v3.0 7.4 High
- CVSS v2 6.5 Medium
- KEV no
- EPSS no
- SSVC no
Attack Vector Network
Attack Complexity Low
Privileges Required Low
Attack Requirements None
User Interaction None
Vulnerable System Confidentiality Impact Low
Vulnerable System Integrity Impact Low
Vulnerable System Availability Impact Low
Subsequent System Confidentiality Impact Low
Subsequent System Integrity Impact Low
Subsequent System Availability Impact Low
Attack Vector Network
Attack Complexity Low
Privileges Required Low
Scope Changed
Confidentiality Impact Low
Integrity Impact Low
Availability Impact Low
User Interaction None
Attack Vector Network
Attack Complexity Low
Privileges Required Low
Scope Changed
Confidentiality Impact Low
Integrity Impact Low
Availability Impact Low
User Interaction None
Access Vector Network
Access Complexity Low
Authentication Single
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
This CVE is not in the KEV list.
No EPSS score available.
Key SSVC decision points have not yet been added.
Mon, 17 Aug 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500, MT3000, MT3600BE, MT5000, MT6000, X2000, X3000 and XE3000 up to 4.8.x. Affected by this issue is the function ui.update_langs of the component Language Update. Performing a manipulation of the argument hour/min/week results in code injection. The attack can be initiated remotely. The vendor explains: "After our investigation, we have confirmed that the vulnerability described (...) does indeed exist." | |
| Title | GL.iNet XE3000 Language Update ui.update_langs code injection | |
| First Time appeared |
Gl.inet
Gl.inet a1300 Gl.inet ax1800 Gl.inet axt1800 Gl.inet be10000 Gl.inet be1400 Gl.inet be3600 Gl.inet be6500 Gl.inet be9300 Gl.inet e5800 Gl.inet mt2500 Gl.inet mt3000 Gl.inet mt3600be Gl.inet mt5000 Gl.inet mt6000 Gl.inet x2000 Gl.inet x3000 Gl.inet xe3000 |
|
| Weaknesses | CWE-74 CWE-94 |
|
| CPEs | cpe:2.3:a:gl.inet:a1300:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:ax1800:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:axt1800:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:be10000:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:be1400:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:be3600:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:be6500:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:be9300:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:e5800:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:mt2500:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:mt3000:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:mt3600be:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:mt5000:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:mt6000:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:x2000:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:x3000:*:*:*:*:*:*:*:* cpe:2.3:a:gl.inet:xe3000:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Gl.inet
Gl.inet a1300 Gl.inet ax1800 Gl.inet axt1800 Gl.inet be10000 Gl.inet be1400 Gl.inet be3600 Gl.inet be6500 Gl.inet be9300 Gl.inet e5800 Gl.inet mt2500 Gl.inet mt3000 Gl.inet mt3600be Gl.inet mt5000 Gl.inet mt6000 Gl.inet x2000 Gl.inet x3000 Gl.inet xe3000 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Subscriptions
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-17T03:45:07.917Z
Reserved: 2026-08-16T13:38:15.897Z
Link: CVE-2026-19980
No data.
Status : Received
Published: 2026-08-17T04:16:56.250
Modified: 2026-08-17T04:16:56.250
Link: CVE-2026-19980
No data.
OpenCVE Enrichment
Updated: 2026-08-17T05:30:16Z