SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-15427

HIGH · CVSS 8.1 EPSS 0.55% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

The Archer VX1800v v1 is vulnerable due to an OS command injection flaw in its TR-069/CWMP management interface, stemming from inadequate input validation and sanitization. If exploited, this vulnerability could enable an attacker to execute arbitrary commands with root privileges, potentially leading to full device compromise. Organizations using this device, particularly those with TR-069 enabled and control over the ACS server, should prioritize remediation efforts to mitigate the risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15427
Severity
HIGH
CVSS
8.1
EPSS
0.55%

Original NVD Description

An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insufficient input validation and sanitization of parameters, allowing crafted input to be executed as system-level commands. Exploitation requires specific conditions such as TR-069 being enabled and ability to influence ACS-delivered commands, compromise or control an ACS server. Successful exploitation may allow arbitrary command execution with root privileges, resulting in complete compromise of the device.

Related CVEs

Other vulnerabilities affecting the same vendor(s)