PT-2026-58110 · Tp Link Systems+1 · Archer Vx1800V V1+1
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Archer VX800v version 1
Description
An OS command injection issue exists due to insufficient input sanitization of the domain name parameter. An adjacent attacker with access to the HTTP interface can inject shell metacharacters into the
domain name parameter, leading to arbitrary code execution with root privileges and complete compromise of the device.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Archer Vx1800V V1
Archer Vx1800V Firmware