Command Injection Vulnerability in TP-Link Networking Devices
CVE-2017-15617
7.2HIGH
Summary
The identified vulnerability in TP-Link WVR, WAR, and ER devices permits remote authenticated administrators to execute arbitrary commands. This occurs through command injection vulnerabilities in the iface variable within the interface_wan.lua file. Exploiting this flaw could allow unauthorized actions that threaten the overall integrity and security of the affected devices, making it essential for users to apply necessary security updates and restrict unnecessary administrative access.
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved