Command Injection Vulnerability in TP-Link Networking Devices
CVE-2017-15620
7.2HIGH
Summary
Certain TP-Link networking devices, specifically WVR, WAR, and ER models, are susceptible to a command injection vulnerability resulting from improper handling of the 'new-zone' variable in the ipmac_import.lua file. This flaw allows authenticated remote administrators to execute arbitrary commands on the affected devices, potentially compromising their security and integrity. It is essential for users to ensure their devices are updated and patched against this vulnerability to safeguard against potential exploitation.
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved