OS Command Injection Vulnerability in Archer VX800v by TP-Link
CVE-2026-15428
8.5HIGH
What is CVE-2026-15428?
The Archer VX800v v1 by TP-Link is susceptible to an OS command injection vulnerability stemming from inadequate input sanitization of the domain name parameter. An adjacent attacker, with access to the related HTTP interface, can exploit this flaw by injecting shell metacharacters. This exploitation can lead to arbitrary code execution, potentially allowing the attacker to gain root privileges and fully compromise the device. It is crucial for users to address this vulnerability through the recommended patch to protect their systems from potential threats.
Affected Version(s)
Archer VX1800v v1 Linux 0 < 0.16.0 2.0.0 v6092.0 Build 260521 RC.7927n
