Command Injection Vulnerability in TP-Link Networking Devices
CVE-2017-15622
7.2HIGH
What is CVE-2017-15622?
Remote authenticated administrators of TP-Link WVR, WAR, and ER devices may be exploited through command injection vulnerabilities present in the 'new-mppeencryption' variable located in the pptp_client.lua file. This vulnerability could allow an attacker to execute arbitrary commands, potentially compromising the device's functionality and integrity.