Command Injection Vulnerability in TP-Link Networking Devices
CVE-2017-15620
7.2HIGH
What is CVE-2017-15620?
Certain TP-Link networking devices, specifically WVR, WAR, and ER models, are susceptible to a command injection vulnerability resulting from improper handling of the 'new-zone' variable in the ipmac_import.lua file. This flaw allows authenticated remote administrators to execute arbitrary commands on the affected devices, potentially compromising their security and integrity. It is essential for users to ensure their devices are updated and patched against this vulnerability to safeguard against potential exploitation.