Skip to content
Threat Feed
high advisory

Remote Command Injection in GL.iNet Router Firewall RPC

An OS command injection vulnerability in the Firewall-management RPC component of GL.iNet BE9300 and MT6000 routers allows remote, unauthenticated attackers to execute arbitrary system commands via crafted network parameters.

CVE search metadata

CVE search record: CVE-2026-19982. Severity: high. CVSS: 7.4. KEV: no. Product: BE9300 (4.8.x), MT6000 (4.8.x). Brief: Remote Command Injection in GL.iNet Router Firewall RPC. Brief link: https://feed.craftedsignal.io/briefs/2026-08-glinet-rce/

Researchers have identified a critical security vulnerability (CVE-2026-19982) affecting GL.iNet BE9300 and MT6000 series routers running firmware version 4.8.x. The flaw exists within the Firewall-management Remote Procedure Call (RPC) component. An unauthenticated remote attacker can exploit this by sending specially crafted requests containing malicious input in the 'dest_port' or 'dest_ip' arguments. This manipulation leads to OS command injection, granting the attacker the ability to execute arbitrary code with the privileges of the underlying firmware process. GL.iNet has confirmed the vulnerability and released firmware version 4.9.0 to address the flaw. Defenders should prioritize updating internet-facing devices and restricting management interface access to trusted networks.

Impact

Successful exploitation allows for full system compromise of the affected router, potentially leading to unauthorized network access, data exfiltration, or the establishment of persistent backdoors within the user's network environment. The vulnerability impacts specific high-performance router models commonly deployed in enterprise and small office environments.

Recommendation

  • Immediately upgrade all GL.iNet BE9300 and MT6000 devices to firmware version 4.9.0.
  • Restrict access to the router management interface (RPC/Web UI) to authorized, internal IP addresses only.
  • Monitor firewall logs for anomalous RPC requests containing shell metacharacters (e.g., ;, |, &, $, `) within the 'dest_port' or 'dest_ip' parameter fields.

Immediate actions

Upgrade affected GL.iNet firmware to 4.9.0 to mitigate CVE-2026-19982

IT Operations 24h

Mitigations

Restrict remote access to router management RPC interfaces

immediate IT Operations

CVE-2026-19982