CVE-2017-15625: Command Injection
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-olmode variable in the pptpclient.lua file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15625?
CVE-2017-15625 has been assigned a severity rating due to its potential for remote command execution.
How do I fix CVE-2017-15625?
To fix CVE-2017-15625, update your TP-Link device firmware to the latest version that addresses this vulnerability.
Which TP-Link devices are affected by CVE-2017-15625?
CVE-2017-15625 affects various TP-Link WVR, WAR, and ER devices, specifically those running vulnerable firmware versions.
Can CVE-2017-15625 be exploited remotely?
Yes, CVE-2017-15625 allows remote authenticated administrators to exploit the vulnerability through command injection.
What type of vulnerability is CVE-2017-15625?
CVE-2017-15625 is a command injection vulnerability that can allow unauthorized command execution on affected devices.