Junglewise Threat Intelligence

CVE-2026-15429: TP-Link Archer VX1800v privilege escalation in HTTP authentication

CVE-2026-15429 · Severity: info · CVSS 5.1 · Published 2026-07-14

Technologies: TP-Link Archer VX1800v. Vendors: TP-Link.

Executive brief

A security vulnerability exists in the TP-Link Archer VX1800v router, a device used for high-speed internet connectivity. An attacker who already has basic user access to the router's management interface can exploit this flaw to elevate their permissions to a full administrator. This could allow them to change critical account settings and take control of the device's configuration.

Technical details

A privilege escalation vulnerability (CWE-93) exists in the HTTP authentication component of the TP-Link Archer VX1800v v1. The root cause is improper neutralization of CRLF sequences (newline characters) in user-controlled input, which are then used to construct internal configuration data. An attacker with low-privileged authenticated access to the device's management interface via an adjacent network can exploit this to modify account settings. Successful exploitation allows the attacker to elevate their privileges to an administrative level. TP-Link has released firmware version 0.16.0 2.0.0 v6092.0 Build 260521 RC.7927n or later to address this issue.

Affected products

  • TP-Link Archer VX1800v v1 < 0.16.0 2.0.0 v6092.0 Build 260521 RC.7927n

Timeline

  • 2026-07-14: advisory: TP-Link and NVD published the advisory.
  • 2026-05-21: patched: Firmware build date for the fix.

References

Related threats