top of page
perceptive_background_267k.jpg

A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.lua of the …

Published:

3 August 2026 at 22:00:00

Alert date:

4 August 2026 at 18:03:19

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Network Infrastructure

A command injection vulnerability has been identified in GL.iNet AX1800 router firmware up to version 4.8.3. The vulnerability exists in the remove_rule function within the file /usr/share/gl-ngx/oui-rpc.lua at the RPC Endpoint component. Attackers can exploit this by manipulating the args.id argument to inject arbitrary commands. The attack can be performed remotely without physical access to the device. A public exploit is already available, increasing the risk of active exploitation. The vendor was notified early in the disclosure process. This vulnerability poses a significant threat to users of the affected GL.iNet AX1800 routers running unpatched firmware versions.

Technical details

Mitigation steps:

Affected products:

GL.iNet AX1800 up to 4.8.3

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page