Executive brief
A security vulnerability exists in the TP-Link Archer VX1800v v1 router, a device used to provide internet connectivity and Wi-Fi. An attacker on the same local network with administrative access can exploit a flaw in the domain name configuration settings to take full control of the device. If successful, the attacker could monitor network traffic, disrupt internet service, or use the compromised router as a foothold to attack other devices on the network.
Technical details
An OS command injection vulnerability (CWE-78) exists in the TP-Link Archer VX1800v v1 due to insufficient input sanitization of the domain name parameter within the HTTP management interface. An attacker located on the adjacent network (local network) who possesses high-level administrative privileges can inject shell metacharacters into this parameter. This results in the execution of arbitrary system commands with root-level permissions. The vulnerability is addressed in firmware version 0.16.0 2.0.0 v6092.0 Build 260521 RC.7927n and later.
Affected products
- TP-Link Archer VX1800v v1 < 0.16.0 2.0.0 v6092.0 Build 260521 RC.7927n
Timeline
- 2026-07-14: disclosed: Advisory published by TP-Link and NVD record created.
- 2026-07-14: patched: Firmware update released to address the vulnerability.