Command Injection Vulnerability in TP-Link Networking Devices
CVE-2017-15637
7.2HIGH
What is CVE-2017-15637?
TP-Link networking devices, specifically WVR, WAR, and ER series, are susceptible to a command injection vulnerability that allows remote authenticated administrators to execute arbitrary commands. This security issue arises through the manipulation of the pptphellointerval variable in the pptp_server.lua file, potentially leading to unauthorized access and control over the affected devices.