OS Command Injection Vulnerability in Archer VX1800v from TP-Link
CVE-2026-15427
8.6HIGH
What is CVE-2026-15427?
The Archer VX1800v v1 by TP-Link is susceptible to an OS command injection vulnerability in its TR-069/CWMP management interface. This flaw arises from inadequate input validation and sanitization of parameters. Attackers who can manipulate ACS-delivered commands and have TR-069 enabled could execute crafted input as system-level commands, potentially allowing arbitrary command execution with elevated privileges. This could lead to a complete compromise of the device and significant risks to network security.
Affected Version(s)
Archer VX1800v v1 Linux 0 < 0.16.0 2.0.0 v6092.0 Build 260521 RC.7927n
