Impact
An OS command injection flaw exists in the domain name parameter of the TP‑Link Archer VX1800v’s TR‑069 management interface. Insufficient sanitization allows an attacker with HTTP access to inject shell metacharacters, leading to arbitrary code execution with root privileges. The vulnerability is classified as CWE‑78. Successful exploitation could fully compromise the device, affecting confidentiality, integrity, and availability.
Affected Systems
TP‑Link Systems Inc. Archer VX1800v model version 1 is affected. The flaw resides in the firmware of this router and is not present in other TP‑Link models that are not listed.
Risk and Exploitability
With a CVSS score of 8.5 the flaw is considered high severity. The EPSS score is less than 1 percent, indicating a low but non‑zero likelihood of exploitation in the wild, and it is not listed in the CISA KEV catalog. Attackers would need to reach the device’s HTTP management interface, which is typically exposed to local or even external networks, and then manipulate the domain name field to inject commands. The resulting remote code execution grants root privileges, offering a complete takeover of the device.
OpenCVE Enrichment