CVE-2026-15428

Severity CVSS v4.0:
HIGH
Type:
CWE-78 OS Command Injections
Publication date:
14/07/2026
Last modified:
06/08/2026

Description

An OS<br /> command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of<br /> the domain name parameter. An adjacent attacker who can access the relevant<br /> HTTP interface can modify the parameter to inject shell metacharacters, resulting<br /> in arbitrary code execution with root privileges.<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> Successful<br /> exploitation may allow remote code execution and complete compromise of the<br /> device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tp-link:archer_vx1800v_firmware:*:*:*:*:*:*:*:* 0.16.0 (excluding)
cpe:2.3:o:tp-link:archer_vx1800v_firmware:2.0.0:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_vx1800v:1.0:*:*:*:*:*:*:*