CVE-2026-19982 | GL.iNet BE9300/MT6000 4.8.x Firewall-management RPC dest_port/dest_ip os command injection
A vulnerability has been found in GL.iNet BE9300 and MT6000 4.8.x and classified as critical. This vulnerability affects unknown code of the component Firewall-management RPC. The manipulation of the argument dest_port/dest_ip leads to os command injection.
This vulnerability is listed as CVE-2026-19982. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
The vendor explains: “After our investigation, we have confirmed that the vulnerability described (…) does indeed exist.”VulDB Recent EntriesRead More