Impact
A flaw in the HTTP authentication handling of TP‑Link Archer VX1800v v1, classified as CWE‑93, allows an attacker to inject newline characters into configuration data constructed internally, enabling the attacker to alter account settings and potentially gain elevated administrative privileges. The vulnerability arises from improper input sanitization and results in a privilege escalation that could compromise the device’s control and security settings.
Affected Systems
TP‑Link Systems Inc. products Archer VX1800v v1 are affected. No other vendors or product versions are listed in the CNA data.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not currently listed in CISA’s KEV catalog. This vulnerability is a CWE‑93 type flaw for improper handling of escaped characters. Exploitation requires an authenticated user that already has sufficient privileges to modify configuration; thus the attack vector is limited to legitimate users who can exploit the input handling flaw.
OpenCVE Enrichment