What is CVE-2026-18787?
CVE-2026-18787 is a command injection vulnerability in GL.iNet AX1800 devices up to v4.8.3, affecting the remove_rule function in /usr/share/gl-ngx/oui-rpc.lua via the RPC endpoint. Remote attackers can exploit it by manipulating the args.id argument. Update to the latest firmware to mitigate.
Azərbaycanca: CVE-2026-18787, GL.iNet AX1800 cihazlarının 4.8.3 versiyasına qədər olan /usr/share/gl-ngx/oui-rpc.lua faylındakı remove_rule funksiyası vasitəsilə command injection zəifliyidir. Bu, uzaqdan hücum edənə args.id parametrini manipulyasiya edərək əmr yeritməyə imkan verir. Cihazı son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77; shared vendor: GL.iNet
FAQ2
Which devices are affected by CVE-2026-18787?
This command injection vulnerability affects GL.iNet AX1800 devices up to version 4.8.3.
How to protect against CVE-2026-18787?
To protect against this vulnerability, update your GL.iNet AX1800 device to the latest firmware version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.