8.8

CVE-2026-15429

Privilege Escalation via Improper Input Sanitization in TP-Link Archer VX1800v

A privilege escalation vulnerability exists in the HTTP authentication component in Archer VX1800v v1. Improper handling of user-controlled input may allow newline characters to be injected into internally constructed configuration data. 









An
authenticated user with sufficient privileges may be able to modify account
settings and gain elevated administrative privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tp-link ≫ Archer Vx1800v Firmware Version < 0.16.0
   Tp-link ≫ Archer Vx1800v Version 1.0
Tp-link ≫ Archer Vx1800v Firmware Version 2.0.0
   Tp-link ≫ Archer Vx1800v Version 1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.84% 0.545
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
f23511db-6c3e-4e32-a477-6aa17d310630 5.1 0 0
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')

The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

https://www.tp-link.com/en/support/download/archer-vx1800v/#Firmware
Product
https://www.tp-link.com/us/support/faq/5189/
Vendor Advisory