High severity8.1NVD Advisory· Published Jul 14, 2026· Updated Aug 6, 2026
CVE-2026-15427
CVE-2026-15427
Description
An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and sanitization of parameters, allowing crafted input to be executed as system-level commands. Exploitation requires specific conditions such as TR-069 being enabled and ability to influence ACS-delivered commands, compromise or control an ACS server.
Successful exploitation may allow arbitrary command execution with root privileges, resulting in complete compromise of the device.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:o:tp-link:archer_vx1800v_firmware:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:tp-link:archer_vx1800v_firmware:*:*:*:*:*:*:*:*range: <0.16.0
- cpe:2.3:o:tp-link:archer_vx1800v_firmware:2.0.0:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- www.tp-link.com/us/support/faq/5189/nvdVendor Advisory
- www.tp-link.com/en/support/download/archer-vx1800v/nvdProduct
News mentions
0No linked articles in our index yet.