CVE-2017-15617: Command Injection
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the iface variable in the interfacewan.lua file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15617?
CVE-2017-15617 is considered a critical vulnerability due to its potential to allow unauthorized command execution.
How do I fix CVE-2017-15617?
To fix CVE-2017-15617, update the affected TP-Link devices' firmware to the latest version provided by the manufacturer.
Which TP-Link devices are affected by CVE-2017-15617?
CVE-2017-15617 affects various TP-Link WVR, WAR, and ER series devices, particularly those with vulnerable firmware.
Can CVE-2017-15617 be exploited remotely?
Yes, CVE-2017-15617 can be exploited remotely by authenticated administrators, enabling them to execute arbitrary commands.
What is the cause of CVE-2017-15617?
CVE-2017-15617 is caused by a command injection vulnerability in the iface variable within the interface_wan.lua file.