Impact
The vulnerability resides in the remove_rule function of the oui-rpc.lua script on GL.iNet AX1800 routers. By manipulating the args.id parameter, an attacker can inject arbitrary shell commands, allowing full remote execution on the device. The weakness is characterized by CWE-74 (Command Injection) and CWE-77 (Improper Handling of Command Construction).
Affected Systems
GL.iNet AX1800 routers running firmware versions up to 4.8.3 are affected. No other vendor or product versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 8.7 classifies this issue as high severity, and the vulnerability can be exploited remotely via the RPC endpoint. Because the exploit is publicly available and no mitigations from the vendor have been documented in this entry, the attack likelihood is significant. The EPSS score is 2%, and the vulnerability is not currently included in the CISA KEV catalog, but its remote attack vector and high severity suggest that organizations using the affected devices should consider immediate remediation.
OpenCVE Enrichment