Description
An OS command
injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and sanitization of
parameters, allowing crafted input to be executed as system-level commands.
Exploitation requires specific conditions such as TR-069 being enabled and ability
to influence ACS-delivered commands, compromise or control an ACS server.





Successful
exploitation may allow arbitrary command execution with root privileges,
resulting in complete compromise of the device.
Published: 2026-07-14
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An OS command injection flaw exists in the TR‑069/CWMP management interface of TP‑Link Archer VX1800v v1. Insufficient input validation and sanitization allow a crafted input to be executed as a system command, potentially granting attacker root‑level control of the device. The vulnerability is identified as CWE‑78. Successful exploitation would give the attacker arbitrary command execution, leading to full compromise of the router’s firmware and network access.

Affected Systems

The Archer VX1800v v1 model from TP‑Link Systems Inc. is affected when the TR‑069 interface is enabled. Firmware that exposes this interface without proper input filtering is vulnerable. The CVE does not specify whether other firmware revisions or models are affected, so the known affected scope is limited to the stated product, but uncertainty remains regarding additional versions.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity, while the EPSS score of less than 1% shows a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires remote access through the TR‑069 protocol, the feature to be enabled on the device, and either the attacker’s ability to influence ACS‑delivered commands or control of the ACS server. Because the attack vector is remote and only active when TR‑069 is enabled, the risk depends on whether the interface is necessary for operation and the network topology exposing it.

Generated by OpenCVE AI on July 31, 2026 at 09:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade router firmware to the latest TP‑Link release that addresses the command‑injection flaw
  • Disable the TR‑069/CWMP interface to eliminate the attack surface
  • Restrict TR‑069 access to trusted IP addresses or a firewall rule, minimizing lateral movement from compromised ACS servers

Generated by OpenCVE AI on July 31, 2026 at 09:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link archer Vx1800v V1
Vendors & Products Tp-link
Tp-link archer Vx1800v V1

Wed, 15 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and sanitization of parameters, allowing crafted input to be executed as system-level commands. Exploitation requires specific conditions such as TR-069 being enabled and ability to influence ACS-delivered commands, compromise or control an ACS server. Successful exploitation may allow arbitrary command execution with root privileges, resulting in complete compromise of the device.
Title OS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer VX1800v
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tp-link Archer Vx1800v V1
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-07-15T03:59:48.164Z

Reserved: 2026-07-10T16:59:14.788Z

Link: CVE-2026-15427

cve-icon Vulnrichment

Updated: 2026-07-14T17:48:24.892Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:00:05Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')