Command Injection Vulnerability in TP-Link WVR, WAR and ER Devices
CVE-2017-15632
7.2HIGH
What is CVE-2017-15632?
TP-Link WVR, WAR, and ER devices are susceptible to a command injection flaw that allows authenticated remote administrators to execute arbitrary commands through manipulation of the new-mppeencryption variable in the pptp_server.lua file. This vulnerability can lead to unauthorized access and control over the affected devices, highlighting the importance of securing such network equipment.