Description
A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may allow newline characters to be injected into internally constructed configuration data. 









An
authenticated user with sufficient privileges may be able to modify account
settings and gain elevated administrative privileges.
Published: 2026-07-14
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the HTTP authentication handling of TP‑Link Archer VX1800v v1, classified as CWE‑93, allows an attacker to inject newline characters into configuration data constructed internally, enabling the attacker to alter account settings and potentially gain elevated administrative privileges. The vulnerability arises from improper input sanitization and results in a privilege escalation that could compromise the device’s control and security settings.

Affected Systems

TP‑Link Systems Inc. products Archer VX1800v v1 are affected. No other vendors or product versions are listed in the CNA data.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not currently listed in CISA’s KEV catalog. This vulnerability is a CWE‑93 type flaw for improper handling of escaped characters. Exploitation requires an authenticated user that already has sufficient privileges to modify configuration; thus the attack vector is limited to legitimate users who can exploit the input handling flaw.

Generated by OpenCVE AI on July 31, 2026 at 09:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update for the Archer VX1800v v1 from TP‑Link’s official download page
  • Restrict privileged account use and enforce role‑based access controls to prevent unauthorized configuration changes
  • Configure the device to disallow or escape newline characters in configuration inputs, and verify that HTTP authentication data is correctly sanitized before processing

Generated by OpenCVE AI on July 31, 2026 at 09:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link archer Vx1800v V1
Vendors & Products Tp-link
Tp-link archer Vx1800v V1

Tue, 14 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may allow newline characters to be injected into internally constructed configuration data.  An authenticated user with sufficient privileges may be able to modify account settings and gain elevated administrative privileges.
Title Privilege Escalation via Improper Input Sanitization in TP-Link Archer VX1800v
Weaknesses CWE-93
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Tp-link Archer Vx1800v V1
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-07-15T03:59:52.199Z

Reserved: 2026-07-10T16:59:17.389Z

Link: CVE-2026-15429

cve-icon Vulnrichment

Updated: 2026-07-14T17:53:08.683Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:00:05Z

Weaknesses
  • CWE-93

    Improper Neutralization of CRLF Sequences ('CRLF Injection')