Impact
An OS command injection flaw exists in the TR‑069/CWMP management interface of TP‑Link Archer VX1800v v1. Insufficient input validation and sanitization allow a crafted input to be executed as a system command, potentially granting attacker root‑level control of the device. The vulnerability is identified as CWE‑78. Successful exploitation would give the attacker arbitrary command execution, leading to full compromise of the router’s firmware and network access.
Affected Systems
The Archer VX1800v v1 model from TP‑Link Systems Inc. is affected when the TR‑069 interface is enabled. Firmware that exposes this interface without proper input filtering is vulnerable. The CVE does not specify whether other firmware revisions or models are affected, so the known affected scope is limited to the stated product, but uncertainty remains regarding additional versions.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity, while the EPSS score of less than 1% shows a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires remote access through the TR‑069 protocol, the feature to be enabled on the device, and either the attacker’s ability to influence ACS‑delivered commands or control of the ACS server. Because the attack vector is remote and only active when TR‑069 is enabled, the risk depends on whether the interface is necessary for operation and the network topology exposing it.
OpenCVE Enrichment