Command Injection Vulnerability in TP-Link Network Devices
CVE-2017-15618
7.2HIGH
What is CVE-2017-15618?
TP-Link WVR, WAR, and ER devices contain a command injection flaw that enables a remote authenticated administrator to execute arbitrary commands. This vulnerability arises from improper handling of the 'new-enable' variable in the pptp_client.lua file, adversely affecting device security and potentially allowing attackers to manipulate device operations.