Tp Link Systems · Archer Vx1800V V1 · CVE-2026-15427
**Name of the Vulnerable Software and Affected Versions**
Archer VX1800v version v1
**Description**
An OS command injection issue exists in the TR-069 / CWMP management interface. This occurs because of insufficient input validation and sanitization of parameters, which allows crafted input to be executed as system-level commands. Exploitation requires TR-069 to be enabled and the ability to influence ACS-delivered commands, such as by compromising or controlling an ACS server. Successful exploitation may allow arbitrary command execution with root privileges, leading to a complete compromise of the device.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.