CVE-2026-15429
MEDIUM 5.1 ALL-YEARSA privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may allow newline characters to be injected into internally constructed configuration data. An authenticated user with sufficient privileges may be able to modify account settings and gain elevated administrative privileges.
No known exploitation, public exploit, or elevated probability at this time. Track for changes.
Exploitation likelihood
0.8%chance of exploitation in 30 days · 55th percentile
Impact if exploited
5.1CVSS 4.0 · MEDIUM · CNA
- ConfidentialityLow
- IntegrityLow
- AvailabilityLow
What an attacker needs
- ⚠Access: Must sit on the same / adjacent network
- ⚠Privileges: Requires a low-privilege account
- ✓User interaction: No user interaction needed
- ✓Complexity: No special conditions — reliably repeatable
- ✓Requirements: No special attack requirements
✓ lowers the bar for an attacker · ⚠ raises it
Proof of concept & exploit code
No public exploit or proof-of-concept code is catalogued for this CVE (no ExploitDB, Nuclei, or CISA-KEV entry). It may still exist — search GitHub or check the references below.
Affected
Vendors Tp Link Systems Inc. Tp Link
Products Archer Vx1800v V1 Archer Vx1800v Firmware Archer Vx1800v
Weakness (CWE)
- CWE-93: Improper neutralization of CRLF sequences ('CRLF injection')
CVSS vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Known Affected Software Configurations
| Vendor | Product | Version range |
|---|---|---|
| Tp Link | Archer Vx1800v Firmware | < 0.16.0 |
| Tp Link | Archer Vx1800v Firmware | 2.0.0 |
All CVSS metrics
- MEDIUM 5.1 v4.0 · CNA Primary
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N - MEDIUM 5.1 v4.0 · NVD Secondary
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - HIGH 8.8 v3.1 · NVD Primary
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H