Remote Command Execution Vulnerability in TP-Link WVR, WAR, and ER Devices
CVE-2017-15629
7.2HIGH
What is CVE-2017-15629?
A command injection vulnerability exists in TP-Link WVR, WAR, and ER devices that permits remote authenticated administrators to execute arbitrary commands. This vulnerability arises from improper validation of the 'new-tunnelname' variable in the 'pptp_client.lua' file, exposing the system to potential unauthorized command execution. This weakness highlights the importance of maintaining secure coding practices and regular updates to network devices to mitigate exploitation risks.