CVE-2017-15628: Command Injection
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the lcpechointerval variable in the pptpserver.lua file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15628?
CVE-2017-15628 has a medium severity rating due to its potential for remote command execution by authenticated users.
How do I fix CVE-2017-15628?
To remediate CVE-2017-15628, update the firmware of your TP-Link devices to the latest patched version provided by the manufacturer.
Which devices are affected by CVE-2017-15628?
CVE-2017-15628 affects multiple TP-Link router models, including the WVR, WAR, and ER series devices.
Can CVE-2017-15628 be exploited remotely?
Yes, CVE-2017-15628 can be exploited remotely by authenticated administrators through command injection.
Is CVE-2017-15628 a common vulnerability?
While CVE-2017-15628 is specific to TP-Link devices, command injection vulnerabilities are a common threat across various software.