Command Injection Vulnerability in TP-Link Networking Devices
CVE-2017-15635
7.2HIGH
What is CVE-2017-15635?
TP-Link's WVR, WAR, and ER series of networking devices face a security issue that allows remote authenticated administrators to execute arbitrary commands. This vulnerability arises from improper handling of the max_conn variable in the session_limits.lua file, leading to potential unauthorized actions within the affected devices. Administrators should promptly assess their systems and apply available patches to mitigate risk.