<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>MT3000 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/mt3000/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 17 Aug 2026 04:43:39 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/mt3000/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in GL.iNet WebDAV Service</title><link>https://feed.craftedsignal.io/briefs/2026-08-glinet-webdav-auth-bypass/</link><pubDate>Mon, 17 Aug 2026 04:43:39 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-glinet-webdav-auth-bypass/</guid><description>Multiple GL.iNet router models running firmware versions up to 4.8.x contain an authorization bypass vulnerability in the WebDAV service, allowing remote unauthenticated attackers to manipulate file operations.</description><content:encoded><![CDATA[<p>GL.iNet has confirmed an authorization bypass vulnerability identified as CVE-2026-19979 affecting numerous router models, including the A1300, AX1800, AXT1800, BE series, E5800, MT series, and X series. The issue resides within the WebDAV service component of the device firmware. Specifically, the flaw exists in the processing of the COPY and MOVE functions, which are improperly validated. This vulnerability allows a remote, unauthenticated attacker to manipulate these functions to circumvent existing access controls. By exploiting this flaw, an attacker can perform unauthorized file operations on the router's file system. Given the remote accessibility of the WebDAV interface, organizations and individual users should treat this as a significant security risk. Affected devices running firmware versions up to 4.8.x are susceptible.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability results in an authorization bypass, enabling unauthorized file manipulation on the target router. This can lead to the exfiltration of sensitive configuration files, unauthorized data modification, or the potential deployment of malicious payloads if file upload paths are leveraged. The impact is critical for administrative integrity of network edge devices.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update all affected GL.iNet router firmware to version 4.8.x or the latest available stable release provided by the vendor.</li>
<li>Disable the WebDAV service on all GL.iNet devices if it is not explicitly required for business operations.</li>
<li>Restrict access to the router's management interfaces and administrative services to trusted management subnets or via VPN only, preventing exposure to the internet.</li>
<li>Audit network logs for unauthorized HTTP/WebDAV methods (COPY, MOVE) originating from external IP addresses toward managed infrastructure.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>cve-2026-19980</category><category>remote-code-execution</category><category>network-security</category><category>firmware-vulnerability</category><category>vulnerability</category><category>rce</category><category>network-infrastructure</category></item></channel></rss>