CVE-2017-15635: Command Injection
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the maxconn variable in the sessionlimits.lua file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15635?
CVE-2017-15635 has a severity rating that indicates it could allow an attacker to execute arbitrary commands on affected TP-Link devices.
How do I fix CVE-2017-15635?
To mitigate CVE-2017-15635, update your TP-Link device firmware to the latest version provided by the manufacturer.
What devices are affected by CVE-2017-15635?
CVE-2017-15635 affects specific firmware versions of TP-Link WVR, WAR, and ER devices.
What kind of attack does CVE-2017-15635 enable?
CVE-2017-15635 enables remote authenticated administrators to perform command injection attacks via the max_conn variable.
Is there a known exploit for CVE-2017-15635?
Yes, CVE-2017-15635 has been documented with known exploit vectors that can take advantage of the command injection vulnerability.