Description
An OS
command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of
the domain name parameter. An adjacent attacker who can access the relevant
HTTP interface can modify the parameter to inject shell metacharacters, resulting
in arbitrary code execution with root privileges.









Successful
exploitation may allow remote code execution and complete compromise of the
device.
Published: 2026-07-14
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An OS command injection flaw exists in the domain name parameter of the TP‑Link Archer VX1800v’s TR‑069 management interface. Insufficient sanitization allows an attacker with HTTP access to inject shell metacharacters, leading to arbitrary code execution with root privileges. The vulnerability is classified as CWE‑78. Successful exploitation could fully compromise the device, affecting confidentiality, integrity, and availability.

Affected Systems

TP‑Link Systems Inc. Archer VX1800v model version 1 is affected. The flaw resides in the firmware of this router and is not present in other TP‑Link models that are not listed.

Risk and Exploitability

With a CVSS score of 8.5 the flaw is considered high severity. The EPSS score is less than 1 percent, indicating a low but non‑zero likelihood of exploitation in the wild, and it is not listed in the CISA KEV catalog. Attackers would need to reach the device’s HTTP management interface, which is typically exposed to local or even external networks, and then manipulate the domain name field to inject commands. The resulting remote code execution grants root privileges, offering a complete takeover of the device.

Generated by OpenCVE AI on July 31, 2026 at 09:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Archer VX1800v router to the latest firmware version provided by TP‑Link that addresses this command injection flaw.
  • Restrict or disable remote access to the router’s management interface, ensuring only trusted local users can access the HTTP control panel.
  • Configure network‑level controls (firewall or VLAN segmentation) to block unsolicited traffic to the router’s management ports from external networks.

Generated by OpenCVE AI on July 31, 2026 at 09:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link archer Vx1800v V1
Vendors & Products Tp-link
Tp-link archer Vx1800v V1

Tue, 14 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. An adjacent attacker who can access the relevant HTTP interface can modify the parameter to inject shell metacharacters, resulting in arbitrary code execution with root privileges. Successful exploitation may allow remote code execution and complete compromise of the device.
Title OS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer VX1800v
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tp-link Archer Vx1800v V1
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-07-15T03:59:51.416Z

Reserved: 2026-07-10T16:59:16.057Z

Link: CVE-2026-15428

cve-icon Vulnrichment

Updated: 2026-07-14T17:50:28.503Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:00:05Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')