{"id":"CVE-2026-15428","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-15428","summary":"An OS\ncommand injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of\nthe domain name parameter. An adjacent attacker who can access the relevant\nHTTP…","details":"An OS\ncommand injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of\nthe domain name parameter. An adjacent attacker who can access the relevant\nHTTP interface can modify the parameter to inject shell metacharacters, resulting\nin arbitrary code execution with root privileges.\n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may allow remote code execution and complete compromise of the\ndevice.","published":"2026-07-14T17:16:44.790","modified":"2026-08-06T18:27:56.630","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.tp-link.com/en/support/download/archer-vx1800v/#Firmware"},{"type":"ADVISORY","url":"https://www.tp-link.com/us/support/faq/5189/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-06T18:27:56.630"}}