CVE-2026-15428: OS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer VX1800v
An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. An adjacent attacker who can access the relevant HTTP interface can modify the parameter to inject shell metacharacters, resulting in arbitrary code execution with root privileges.
Successful exploitation may allow remote code execution and complete compromise of the device.
Affected Software
Event History
Frequently Asked Questions
What are the risks associated with CVE-2026-15428?
CVE-2026-15428 carries a high severity rating of 8.5, indicating significant risks including arbitrary code execution.
How do I fix CVE-2026-15428?
To mitigate CVE-2026-15428, update the firmware of the TP-Link Archer VX1800v to the latest version provided by the manufacturer.
Who can exploit CVE-2026-15428?
CVE-2026-15428 can be exploited by an adjacent attacker with access to the relevant HTTP management interface.
What type of vulnerability is CVE-2026-15428?
CVE-2026-15428 is classified as an OS Command Injection vulnerability due to improper input sanitization.
What devices are affected by CVE-2026-15428?
CVE-2026-15428 specifically affects the TP-Link Archer VX1800v model.