CVE-2026-15427
HIGH 8.6 ALL-YEARSAn OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and sanitization of parameters, allowing crafted input to be executed as system-level commands. Exploitation requires specific conditions such as TR-069 being enabled and ability to influence ACS-delivered commands, compromise or control an ACS server. Successful exploitation may allow arbitrary command execution with root privileges, resulting in complete compromise of the device.
Severe if exploited (CVSS 8.6), but no confirmed exploitation. Patch on a normal cadence.
Exploitation likelihood
0.6%chance of exploitation in 30 days · 44th percentile
Impact if exploited
8.6CVSS 4.0 · HIGH · CNA
- ConfidentialityHigh
- IntegrityHigh
- AvailabilityHigh
What an attacker needs
- ✓Access: Reachable over the network — no local access needed
- ⚠Privileges: Requires an admin / high-privilege account
- ✓User interaction: No user interaction needed
- ✓Complexity: No special conditions — reliably repeatable
- ✓Requirements: No special attack requirements
✓ lowers the bar for an attacker · ⚠ raises it
Proof of concept & exploit code
No public exploit or proof-of-concept code is catalogued for this CVE (no ExploitDB, Nuclei, or CISA-KEV entry). It may still exist — search GitHub or check the references below.
Affected
Vendors Tp Link Systems Inc. Tp Link
Products Archer Vx1800v V1 Archer Vx1800v Firmware Archer Vx1800v
Weakness (CWE)
- CWE-78: Improper neutralization of special elements used in an OS command ('OS command injection')
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Known Affected Software Configurations
| Vendor | Product | Version range |
|---|---|---|
| Tp Link | Archer Vx1800v Firmware | < 0.16.0 |
| Tp Link | Archer Vx1800v Firmware | 2.0.0 |
All CVSS metrics
- HIGH 8.6 v4.0 · CNA Primary
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - HIGH 8.6 v4.0 · NVD Secondary
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - HIGH 8.1 v3.1 · NVD Primary
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H