CVE-2026-18787
📛 CVE Title
GL.iNet AX1800 RPC Endpoint oui-rpc.lua remove_rule command injection
Description
A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.lua of the component RPC Endpoint. The manipulation of the argument args.id leads to command injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- VulDB
- CVSS severity
- HIGH
- CVSS score
- 8.7 / 10
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P- Effective score
- 8.7 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-77,CWE-74 - Reserved
- 2026-08-04
- Published
- 2026-08-04 17:00 UTC
- Last updated
- 2026-08-04 17:19 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/18xxx/CVE-2026-18787.json
- Linked Threat
- CVE-2026-18787 — GL.iNet AX1800 RPC Endpoint oui-rpc.lua remove_rule command injection
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| GL.iNet | AX1800 |
4.8.0 (affected),
4.8.1 (affected),
4.8.2 (affected),
4.8.3 (affected)
|
— |
Vendor references (5)
References embedded in the original CVE record by the assigning CNA.
- VDB-385788 | GL.iNet AX1800 RPC Endpoint oui-rpc.lua remove_rule command injection vdb-entrytechnical-description
- VDB-385788 | CTI Indicators (IOB, IOC, TTP, IOA) signaturepermissions-required
- CVE-2026-18787 | CVE Analysis and Report third-party-advisory
- Submit #857346 | GL.iNet AX1800 4.8.3 Command Injection third-party-advisory
- https://github.com/xxianxiayubanmian/iot/blob/main/GL-link%20AX1800.md exploit
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-18787.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-18787",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-04T17:18:57.423604Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-04T17:19:14.440Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:o:gl-inet:ax1800_firmware:*:*:*:*:*:*:*:*"
],
"modules": [
"RPC Endpoint"
],
"product": "AX1800",
"vendor": "GL.iNet",
"versions": [
{
"status": "affected",
"version": "4.8.0"
},
{
"status": "affected",
"version": "4.8.1"
},
{
"status": "affected",
"version": "4.8.2"
},
{
"status": "affected",
"version": "4.8.3"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "misaki_ce (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.lua of the component RPC Endpoint. The manipulation of the argument args.id leads to command injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 8.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 9,
"vectorString": "AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-77",
"description": "Command Injection",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-74",
"description": "Injection",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-04T17:00:09.281Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-385788 | GL.iNet AX1800 RPC Endpoint oui-rpc.lua remove_rule command injection",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/385788"
},
{
"name": "VDB-385788 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/385788/cti"
},
{
"name": "CVE-2026-18787 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-18787"
},
{
"name": "Submit #857346 | GL.iNet AX1800 4.8.3 Command Injection",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/857346"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/xxianxiayubanmian/iot/blob/main/GL-link%20AX1800.md"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-08-04T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-08-04T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-08-04T10:38:05.000Z",
"value": "VulDB entry last update"
}
],
"title": "GL.iNet AX1800 RPC Endpoint oui-rpc.lua remove_rule command injection",
"x_generator": [
"VulDB PVTS v202608"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-18787",
"datePublished": "2026-08-04T17:00:09.281Z",
"dateReserved": "2026-08-04T08:33:00.136Z",
"dateUpdated": "2026-08-04T17:19:14.440Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}