Command Injection Vulnerability in TP-Link Network Devices
CVE-2017-15625
7.2HIGH
Summary
The vulnerability allows remote authenticated administrators of TP-Link WVR, WAR, and ER network devices to execute arbitrary commands. This occurs through a command injection flaw in the pptp_client.lua file, specifically in the new-olmode variable. Exploitation of this vulnerability could lead to unauthorized control over the affected devices, highlighting a significant security risk for users and network administrators.
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved