CVE-2017-15624: Command Injection
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-authtype variable in the pptpserver.lua file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15624?
CVE-2017-15624 is classified as a high severity vulnerability due to the potential for remote command execution.
How do I fix CVE-2017-15624?
To fix CVE-2017-15624, update your TP-Link device firmware to the latest version that addresses this vulnerability.
Which devices are affected by CVE-2017-15624?
CVE-2017-15624 affects several TP-Link devices including WVR, WAR, and ER series routers.
What type of vulnerability is CVE-2017-15624?
CVE-2017-15624 is a command injection vulnerability that allows remote authenticated administrators to execute arbitrary commands.
How can I determine if my TP-Link device is vulnerable to CVE-2017-15624?
Check the firmware version of your TP-Link device against known vulnerable versions listed in security advisories for CVE-2017-15624.