CVE-2026-18787

GL.iNet · AX1800

A command injection vulnerability in GL.iNet AX1800 allows authenticated users with low privileges to execute arbitrary system commands, potentially leading to full system compromise.

Executive summary

A command injection vulnerability in GL.iNet AX1800 devices poses a significant risk of remote code execution for authenticated attackers.

Vulnerability

The device suffers from a command injection flaw (CWE-77). An attacker with low-level authenticated access can manipulate input parameters to execute arbitrary OS commands on the underlying system.

Business impact

The ability to execute arbitrary commands on a network device can result in complete system takeover, unauthorized access to internal network segments, and potential data interception. Given the CVSS score of 8.8, this vulnerability is categorized as high severity, as it allows an attacker to pivot from the management interface to the broader infrastructure.

Remediation

Immediate Action: Update the GL.iNet AX1800 firmware to a version beyond 4.8.3 as soon as the vendor provides a patch.

Proactive Monitoring: Monitor device logs for unusual command execution patterns or unexpected shell access attempts by low-privileged user accounts.

Compensating Controls: Restrict administrative and low-level access to the device management interface by placing it on a dedicated management VLAN or using firewall rules to limit access to trusted IP addresses.

Exploitation status

Public Exploit Available: No (no confirmed public weaponized exploit exists in the provided data).

Analyst recommendation

The high CVSS score and the existence of a proof-of-concept mandate immediate attention. Organizations should prioritize updating affected hardware and restricting network access to the management interface to prevent unauthorized exploitation.