Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-15428

Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-78 Neutralización incorrecta de elementos especiales usados en un comando de sistema operativo (Inyección de comando de sistema operativo)
Fecha de publicación:
14/07/2026
Última modificación:
06/08/2026

Descripción

*** Pendiente de traducción *** An OS<br /> command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of<br /> the domain name parameter. An adjacent attacker who can access the relevant<br /> HTTP interface can modify the parameter to inject shell metacharacters, resulting<br /> in arbitrary code execution with root privileges.<br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> Successful<br /> exploitation may allow remote code execution and complete compromise of the<br /> device.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:tp-link:archer_vx1800v_firmware:*:*:*:*:*:*:*:* 0.16.0 (excluyendo)
cpe:2.3:o:tp-link:archer_vx1800v_firmware:2.0.0:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_vx1800v:1.0:*:*:*:*:*:*:*