CVE-2017-15632: Command Injection
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-mppeencryption variable in the pptpserver.lua file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15632?
CVE-2017-15632 is classified as a high severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2017-15632?
To fix CVE-2017-15632, you should update the affected TP-Link devices to the latest firmware version provided by the manufacturer.
Which TP-Link devices are affected by CVE-2017-15632?
CVE-2017-15632 affects multiple TP-Link WVR, WAR, and ER series devices, particularly those using vulnerable firmware versions.
What type of attack can exploit CVE-2017-15632?
CVE-2017-15632 can be exploited through command injection, allowing authenticated remote attackers to execute arbitrary commands on the vulnerable device.
Is my TP-Link device at risk from CVE-2017-15632?
You are at risk if you are using an affected version of the firmware on your TP-Link WVR, WAR, or ER device.