CVE-2026-15428

HIGH

OS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer VX1800v

Title source: cna
STIX 2.1

Description

An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. An adjacent attacker who can access the relevant HTTP interface can modify the parameter to inject shell metacharacters, resulting in arbitrary code execution with root privileges. Successful exploitation may allow remote code execution and complete compromise of the device.

References (2)

Core 2

Scores

CVSS v4 8.5
EPSS 0.0089
EPSS Percentile 55.7%
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
TP-Link Systems Inc./Archer VX1800v v1 < 0.16.0 2.0.0 v6092.0 Build 260521 RC.7927n
Published Jul 14, 2026
Tracked Since Jul 14, 2026