CVE-2017-15626: Command Injection
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-bindif variable in the pptpserver.lua file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15626?
CVE-2017-15626 has been classified with a medium severity level due to the ability of an authenticated user to execute arbitrary commands.
How do I fix CVE-2017-15626?
To fix CVE-2017-15626, TP-Link devices should be updated to the latest firmware version that addresses this vulnerability.
Who is affected by CVE-2017-15626?
CVE-2017-15626 affects specific TP-Link WVR, WAR, and ER devices that have the vulnerable firmware installed.
What exploitation method is used in CVE-2017-15626?
The exploitation method used in CVE-2017-15626 is command injection via the 'new-bindif' variable in the pptp_server.lua file.
Can CVE-2017-15626 be exploited remotely?
Yes, CVE-2017-15626 can be exploited remotely but requires authentication as an administrator.