CVE-2026-18787
Last modified
CVE-2026-18787 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.lua of the component RPC Endpoint.
Description
A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.lua of the component RPC Endpoint. The manipulation of the argument args.id leads to command injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| GL.iNet | AX1800 | 4.8.0; 4.8.1; 4.8.2; 4.8.3 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-18787?
How severe is CVE-2026-18787?
How do I fix CVE-2026-18787?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-18774A flaw has been found in NousResearch hermes-agent up to 0.1…6.3
- CVE-2026-18775A vulnerability has been found in NousResearch hermes-agent …6.3
- CVE-2026-1878An Insufficient Integrity Verification vulnerability in the …5.4
- CVE-2026-18784A vulnerability was found in o6 open62541 up to 1.5.5. This …5.3
- CVE-2026-18785A vulnerability was determined in o6 open62541 ca356b088ada7…5.3
- CVE-2026-18786The CheckView WordPress plugin before 2.3.2 does not restri…8.8
- CVE-2026-18788A security flaw has been discovered in Trippo ResponsiveFile…7.3
- CVE-2026-18789The Ezoic WordPress plugin before 2.23.1 does not properly r…7.5
- CVE-2026-1879A vulnerability was detected in Harvard University IQSS Data…6.3
- CVE-2026-18790A weakness has been identified in Systerel S2OPC up to 1.7.3…3.3
- CVE-2026-1880An Incorrect Permission Assignment for Critical Resource vul…5.4
- CVE-2026-18801OpenMeter contains a stored, or second-order, SQL injection …9.3
Are you affected by CVE-2026-18787?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
