CVE-2017-15629: Command Injection
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-tunnelname variable in the pptpclient.lua file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15629?
CVE-2017-15629 is classified as a critical vulnerability due to its potential for remote command execution.
How can I fix CVE-2017-15629?
To remediate CVE-2017-15629, update the firmware of affected TP-Link devices to the latest version provided by the manufacturer.
What devices are affected by CVE-2017-15629?
CVE-2017-15629 affects several TP-Link devices, including the WVR, WAR, and ER series with specific firmware versions.
Is authentication required to exploit CVE-2017-15629?
Yes, the attacker must be an authenticated administrator to carry out the command injection in CVE-2017-15629.
What is the impact of CVE-2017-15629?
The impact of CVE-2017-15629 includes unauthorized remote code execution, potentially compromising the device and network.