Gl.Inet · Axt1800 · CVE-2026-18787
**Name of the Vulnerable Software and Affected Versions**
GL.iNet AX1800 versions prior to 4.8.4
**Description**
A command injection issue exists in the RPC Endpoint component within the `remove rule()` function of the `/usr/share/gl-ngx/oui-rpc.lua` file. A remote attacker can exploit this by manipulating the `args.id` argument, allowing for the execution of arbitrary commands on the system.
**Recommendations**
Update GL.iNet AX1800 to version 4.8.4 or later.
As a temporary mitigation, restrict access to the RPC Endpoint component to prevent remote manipulation of the `args.id` argument.