


Perceptive Security
SOC/SIEM Consultancy

A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.lua of the …
Published:
4 augustus 2026 om 00:00:00
Alert date:
4 augustus 2026 om 20:03:19
Source:
nvd.nist.gov
Mobile & IoT, Network Infrastructure
A command injection vulnerability has been identified in GL.iNet AX1800 router firmware up to version 4.8.3. The vulnerability exists in the remove_rule function within the file /usr/share/gl-ngx/oui-rpc.lua at the RPC Endpoint component. Attackers can exploit this by manipulating the args.id argument to inject arbitrary commands. The attack can be performed remotely without physical access to the device. A public exploit is already available, increasing the risk of active exploitation. The vendor was notified early in the disclosure process. This vulnerability poses a significant threat to users of the affected GL.iNet AX1800 routers running unpatched firmware versions.
Technical details
Mitigation steps:
Affected products:
GL.iNet AX1800 up to 4.8.3
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18787
https://github.com/xxianxiayubanmian/iot/blob/main/GL-link%20AX1800.md
https://vuldb.com/cve/CVE-2026-18787
https://vuldb.com/submit/857346
https://vuldb.com/vuln/385788
https://vuldb.com/vuln/385788/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
