CVE-2026-15427

Severity CVSS v4.0:
HIGH
Type:
CWE-78 OS Command Injections
Publication date:
14/07/2026
Last modified:
06/08/2026

Description

An OS command<br /> injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and sanitization of<br /> parameters, allowing crafted input to be executed as system-level commands.<br /> Exploitation requires specific conditions such as TR-069 being enabled and ability<br /> to influence ACS-delivered commands, compromise or control an ACS server.<br /> <br /> <br /> <br /> <br /> <br /> Successful<br /> exploitation may allow arbitrary command execution with root privileges,<br /> resulting in complete compromise of the device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tp-link:archer_vx1800v_firmware:*:*:*:*:*:*:*:* 0.16.0 (excluding)
cpe:2.3:o:tp-link:archer_vx1800v_firmware:2.0.0:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_vx1800v:1.0:*:*:*:*:*:*:*