CVE-2017-15613: Command Injection
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-interface variable in the cmxddns.lua file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15613?
CVE-2017-15613 is classified as a high severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2017-15613?
To fix CVE-2017-15613, update the affected TP-Link devices to the latest firmware version provided by the vendor.
Which TP-Link devices are affected by CVE-2017-15613?
CVE-2017-15613 affects various TP-Link WVR, WAR, and ER devices, specifically those with the vulnerable firmware versions.
What kind of attack can be executed using CVE-2017-15613?
CVE-2017-15613 allows attackers to execute arbitrary commands on the device due to command injection vulnerabilities.
Is CVE-2017-15613 exploitable by unauthenticated users?
CVE-2017-15613 requires remote authenticated access for exploitation, which makes it a concern for secured environments.