Command Injection Vulnerability in TP-Link WVR, WAR, and ER Devices
CVE-2017-15626
7.2HIGH
What is CVE-2017-15626?
A command injection vulnerability in TP-Link WVR, WAR, and ER devices allows remote authenticated administrators to execute arbitrary commands. This security flaw arises from improper handling of the new-bindif variable in the pptp_server.lua file, potentially leading to unauthorized command execution within the affected systems. Attackers could exploit this vulnerability to control and manipulate device behavior, compromising the security of the network infrastructure.