An OS command
injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and sanitization of
parameters, allowing crafted input to be executed as system-level commands.
Exploitation requires specific conditions such as TR-069 being enabled and ability
to influence ACS-delivered commands, compromise or control an ACS server.
Successful
exploitation may allow arbitrary command execution with root privileges,
resulting in complete compromise of the device.
References
| Link | Resource |
|---|---|
| https://www.tp-link.com/en/support/download/archer-vx1800v/#Firmware | Product |
| https://www.tp-link.com/us/support/faq/5189/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-07-14 17:16
Updated : 2026-08-06 18:28
NVD link : CVE-2026-15427
Mitre link : CVE-2026-15427
CVE.ORG link : CVE-2026-15427
JSON object : View
Products Affected
tp-link
- archer_vx1800v_firmware
- archer_vx1800v
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
