PT-2026-58110 · Tp Link Systems+1 · Archer Vx1800V V1+1

·

CVE-2026-15428

·

Published

2026-07-14

·

Updated

2026-08-06

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Archer VX800v version 1
Description An OS command injection issue exists due to insufficient input sanitization of the domain name parameter. An adjacent attacker with access to the HTTP interface can inject shell metacharacters into the domain name parameter, leading to arbitrary code execution with root privileges and complete compromise of the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15428

Affected Products

Archer Vx1800V V1
Archer Vx1800V Firmware