A vulnerability has been found in GL.iNet AX1800 up to 4.8.3 and classified as critical. The affected element is the function
remove_rule of the file /usr/share/gl-ngx/oui-rpc.lua of the component RPC Endpoint. The manipulation of the argument args.id leads to command injection.
This vulnerability is uniquely identified as CVE-2026-18787. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure.