OS Command Injection Vulnerability in Archer VX1800v from TP-Link
CVE-2026-15427

8.6HIGH

What is CVE-2026-15427?

The Archer VX1800v v1 by TP-Link is susceptible to an OS command injection vulnerability in its TR-069/CWMP management interface. This flaw arises from inadequate input validation and sanitization of parameters. Attackers who can manipulate ACS-delivered commands and have TR-069 enabled could execute crafted input as system-level commands, potentially allowing arbitrary command execution with elevated privileges. This could lead to a complete compromise of the device and significant risks to network security.

Affected Version(s)

Archer VX1800v v1 Linux 0 < 0.16.0 2.0.0 v6092.0 Build 260521 RC.7927n

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Klamm9
.