{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/ax1800/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-18787"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AX1800"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["GL.iNet"],"content_html":"\u003cp\u003eA command injection vulnerability (CVE-2026-18787) has been identified in GL.iNet AX1800 routers running firmware versions up to 4.8.3. The flaw exists within the RPC endpoint component, specifically in the \u003ccode\u003eremove_rule\u003c/code\u003e function defined in \u003ccode\u003e/usr/share/gl-ngx/oui-rpc.lua\u003c/code\u003e. Attackers can leverage improper neutralization of the \u003ccode\u003eargs.id\u003c/code\u003e argument to inject and execute arbitrary system commands. This vulnerability is remotely exploitable by an authenticated user. Given that public exploit code is available for this vulnerability, defenders should prioritize patching affected devices to the latest available firmware version to mitigate the risk of unauthorized system access and full device compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker establishes an authenticated session with the GL.iNet router web management interface or RPC API.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious request targeting the RPC endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker injects shell metacharacters into the \u003ccode\u003eargs.id\u003c/code\u003e parameter of the \u003ccode\u003eremove_rule\u003c/code\u003e RPC call.\u003c/li\u003e\n\u003cli\u003eThe router's \u003ccode\u003e/usr/share/gl-ngx/oui-rpc.lua\u003c/code\u003e script processes the \u003ccode\u003eargs.id\u003c/code\u003e argument without sufficient input sanitization.\u003c/li\u003e\n\u003cli\u003eThe underlying system passes the unsanitized input to a command execution function, resulting in OS command execution with the privileges of the RPC service.\u003c/li\u003e\n\u003cli\u003eAttacker gains persistent code execution on the router, potentially allowing for lateral movement or traffic interception.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for complete compromise of the affected GL.iNet AX1800 router. Impact includes full control over the device, potential exfiltration of network traffic, and use of the router as a pivot point for further attacks on the internal network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the latest firmware updates provided by GL.iNet for the AX1800 to remediate CVE-2026-18787.\u003c/li\u003e\n\u003cli\u003eRestrict access to the router's management interface and RPC endpoints to trusted IP addresses only.\u003c/li\u003e\n\u003cli\u003eMonitor for suspicious RPC calls to the management interface that deviate from established administrative baseline behavior.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-04T17:25:31Z","date_published":"2026-08-04T17:25:31Z","id":"https://feed.craftedsignal.io/briefs/2026-08-glinet-rce/","summary":"An authenticated remote command injection vulnerability in the RPC component of GL.iNet AX1800 routers (firmware \u003c= 4.8.3) allows attackers to execute arbitrary system commands via the 'remove_rule' function.","title":"Command Injection Vulnerability in GL.iNet AX1800 RPC Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-08-glinet-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - AX1800","version":"https://jsonfeed.org/version/1.1"}