Junglewise Threat Intelligence

CVE-2026-15427: TP-Link Archer VX1800v OS command injection in TR-069 interface

CVE-2026-15427 · Severity: info · CVSS 8.6 · Published 2026-07-14

Technologies: TP-Link Archer VX1800v. Vendors: TP-Link.

Executive brief

TP-Link Archer VX1800v routers are affected by a security flaw in their remote management interface, which is typically used by internet service providers to manage home equipment. If an attacker gains control over the management server used by the provider, they can send malicious commands to the router. Successful exploitation allows the attacker to take full control of the device, potentially leading to data interception or service disruption.

Technical details

An OS command injection vulnerability (CWE-78) exists in the TR-069 (CWMP) management interface of the TP-Link Archer VX1800v v1. The flaw stems from insufficient validation and sanitization of parameters delivered via the CWMP protocol. To exploit this, an attacker must be able to influence commands delivered by an Auto Configuration Server (ACS), which typically requires compromising or controlling the ACS itself. If successful, the attacker can execute arbitrary system-level commands with root privileges, leading to a complete compromise of the Linux-based firmware. The issue is resolved in firmware version 0.16.0 2.0.0 v6092.0 Build 260521 RC.7927n or later.

Affected products

  • TP-Link Archer VX1800v v1 < 0.16.0 2.0.0 v6092.0 Build 260521 RC.7927n

Timeline

  • 2026-07-14: advisory: Initial advisory published by TP-Link and NVD
  • 2026-05-21: patched: Firmware build date for the fix

References

Related threats