CVE-2026-18787 | GL.iNet AX1800 up to 4.8.3 RPC Endpoint oui-rpc.lua remove_rule args.id command injection
A vulnerability has been found in GL.iNet AX1800 up to 4.8.3 and classified as critical. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.lua of the component RPC Endpoint. The manipulation of the argument args.id leads to command injection.
This vulnerability is uniquely identified as CVE-2026-18787. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure.VulDB Recent EntriesRead More