CVE-2026-15428
HIGH 8.5 ALL-YEARSAn OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. An adjacent attacker who can access the relevant HTTP interface can modify the parameter to inject shell metacharacters, resulting in arbitrary code execution with root privileges. Successful exploitation may allow remote code execution and complete compromise of the device.
Severe if exploited (CVSS 8.5), but no confirmed exploitation. Patch on a normal cadence.
Exploitation likelihood
1.0%chance of exploitation in 30 days · 60th percentile
Impact if exploited
8.5CVSS 4.0 · HIGH · CNA
- ConfidentialityHigh
- IntegrityHigh
- AvailabilityHigh
What an attacker needs
- ⚠Access: Must sit on the same / adjacent network
- ⚠Privileges: Requires an admin / high-privilege account
- ✓User interaction: No user interaction needed
- ✓Complexity: No special conditions — reliably repeatable
- ✓Requirements: No special attack requirements
✓ lowers the bar for an attacker · ⚠ raises it
Proof of concept & exploit code
No public exploit or proof-of-concept code is catalogued for this CVE (no ExploitDB, Nuclei, or CISA-KEV entry). It may still exist — search GitHub or check the references below.
Affected
Vendors Tp Link Systems Inc. Tp Link
Products Archer Vx1800v V1 Archer Vx1800v Firmware Archer Vx1800v
Weakness (CWE)
- CWE-78: Improper neutralization of special elements used in an OS command ('OS command injection')
CVSS vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Known Affected Software Configurations
| Vendor | Product | Version range |
|---|---|---|
| Tp Link | Archer Vx1800v Firmware | < 0.16.0 |
| Tp Link | Archer Vx1800v Firmware | 2.0.0 |
All CVSS metrics
- HIGH 8.5 v4.0 · CNA Primary
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - HIGH 8.5 v4.0 · NVD Secondary
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - HIGH 8.8 v3.1 · NVD Primary
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H