Command Injection Vulnerability in TP-Link Networking Devices
CVE-2017-15628
7.2HIGH
What is CVE-2017-15628?
The vulnerability in TP-Link WVR, WAR, and ER devices allows remote authenticated administrators to execute arbitrary commands. This occurs through command injection in the lcpechointerval variable found within the pptp_server.lua file. Exploiting this vulnerability can lead to unauthorized access and manipulation of device functionality, posing significant security risks if left unaddressed.