{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/x2000/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.3,"id":"CVE-2026-19979"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["A1300","AX1800","AXT1800","BE1400","BE3600","BE6500","BE9300","BE10000","E5800","MT2500","MT3000","MT3600BE","MT5000","MT6000","X2000","X3000","XE3000"],"_cs_severities":["high"],"_cs_tags":["cve-2026-19980","remote-code-execution","network-security","firmware-vulnerability","vulnerability","rce","network-infrastructure"],"_cs_type":"advisory","_cs_vendors":["GL.iNet"],"content_html":"\u003cp\u003eGL.iNet has confirmed an authorization bypass vulnerability identified as CVE-2026-19979 affecting numerous router models, including the A1300, AX1800, AXT1800, BE series, E5800, MT series, and X series. The issue resides within the WebDAV service component of the device firmware. Specifically, the flaw exists in the processing of the COPY and MOVE functions, which are improperly validated. This vulnerability allows a remote, unauthenticated attacker to manipulate these functions to circumvent existing access controls. By exploiting this flaw, an attacker can perform unauthorized file operations on the router's file system. Given the remote accessibility of the WebDAV interface, organizations and individual users should treat this as a significant security risk. Affected devices running firmware versions up to 4.8.x are susceptible.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in an authorization bypass, enabling unauthorized file manipulation on the target router. This can lead to the exfiltration of sensitive configuration files, unauthorized data modification, or the potential deployment of malicious payloads if file upload paths are leveraged. The impact is critical for administrative integrity of network edge devices.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate all affected GL.iNet router firmware to version 4.8.x or the latest available stable release provided by the vendor.\u003c/li\u003e\n\u003cli\u003eDisable the WebDAV service on all GL.iNet devices if it is not explicitly required for business operations.\u003c/li\u003e\n\u003cli\u003eRestrict access to the router's management interfaces and administrative services to trusted management subnets or via VPN only, preventing exposure to the internet.\u003c/li\u003e\n\u003cli\u003eAudit network logs for unauthorized HTTP/WebDAV methods (COPY, MOVE) originating from external IP addresses toward managed infrastructure.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-17T06:43:56Z","date_published":"2026-08-17T04:43:39Z","id":"https://feed.craftedsignal.io/briefs/2026-08-glinet-webdav-auth-bypass/","summary":"Multiple GL.iNet router models running firmware versions up to 4.8.x contain an authorization bypass vulnerability in the WebDAV service, allowing remote unauthenticated attackers to manipulate file operations.","title":"Authorization Bypass in GL.iNet WebDAV Service","url":"https://feed.craftedsignal.io/briefs/2026-08-glinet-webdav-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - X2000","version":"https://jsonfeed.org/version/1.1"}