← All CVEs

CVE-2026-15428

HIGH 8.5 ALL-YEARS

Published 2026-07-14 · Last modified 2026-07-15 · TPLink · NVD: Analyzed

An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. An adjacent attacker who can access the relevant HTTP interface can modify the parameter to inject shell metacharacters, resulting in arbitrary code execution with root privileges. Successful exploitation may allow remote code execution and complete compromise of the device.

ELEVATED IMPACT

Severe if exploited (CVSS 8.5), but no confirmed exploitation. Patch on a normal cadence.

Exploitation likelihood

1.0%chance of exploitation in 30 days · 60th percentile

○ In CISA KEV○ Public exploit / PoC◆ SSVC: exploitation none, automatable no

Impact if exploited

8.5CVSS 4.0 · HIGH · CNA

  • ConfidentialityHigh
  • IntegrityHigh
  • AvailabilityHigh

What an attacker needs

  • Access: Must sit on the same / adjacent network
  • Privileges: Requires an admin / high-privilege account
  • User interaction: No user interaction needed
  • Complexity: No special conditions — reliably repeatable
  • Requirements: No special attack requirements

✓ lowers the bar for an attacker · ⚠ raises it

Proof of concept & exploit code

No public exploit or proof-of-concept code is catalogued for this CVE (no ExploitDB, Nuclei, or CISA-KEV entry). It may still exist — search GitHub or check the references below.

Affected

Vendors Tp Link Systems Inc. Tp Link

Products Archer Vx1800v V1 Archer Vx1800v Firmware Archer Vx1800v

Weakness (CWE)

  • CWE-78: Improper neutralization of special elements used in an OS command ('OS command injection')

CVSS vector

CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Known Affected Software Configurations

VendorProductVersion range
Tp LinkArcher Vx1800v Firmware< 0.16.0
Tp LinkArcher Vx1800v Firmware2.0.0

All CVSS metrics

  • HIGH 8.5 v4.0 · CNA Primary
    CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  • HIGH 8.5 v4.0 · NVD Secondary
    CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • HIGH 8.8 v3.1 · NVD Primary
    CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Advisories

Sources: NVD · CVE.org · EPSS