LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-15428

tp-link · archer vx1800v firmware

Published
CVSS8.8
Severityhigh
WeaknessCWE-78
ExploitedNot in CISA KEV

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

An OS command injection vulnerability exists in Archer VX800v v1 due to insufficient input sanitization of the domain name parameter. An adjacent attacker who can access the relevant HTTP interface can modify the parameter to inject shell metacharacters, resulting in arbitrary code execution with root privileges. Successful exploitation may allow remote code execution and complete compromise of the device.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-15428

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-15428.