CVE-2017-15637: Command Injection
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the pptphellointerval variable in the pptpserver.lua file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-15637?
CVE-2017-15637 is considered a high severity vulnerability due to its potential for arbitrary command execution by remote authenticated administrators.
How do I fix CVE-2017-15637?
To fix CVE-2017-15637, update the firmware of affected TP-Link devices to the latest version provided by the vendor.
What devices are affected by CVE-2017-15637?
CVE-2017-15637 affects TP-Link WVR, WAR, and ER series devices that are running vulnerable firmware versions.
Can CVE-2017-15637 be exploited remotely?
Yes, CVE-2017-15637 can be exploited remotely if the attacker has valid administrative credentials.
What type of attack does CVE-2017-15637 enable?
CVE-2017-15637 enables command injection attacks, allowing unauthorized command execution on the affected devices.