VYPR
Unrated severityNVD Advisory· Published Jan 11, 2018· Updated Aug 5, 2024

CVE-2017-15613

CVE-2017-15613

Description

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-interface variable in the cmxddns.lua file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

TP-Link WVR/WAR/ER devices allow authenticated admin RCE via command injection in the cmxddns.lua new-interface variable.

Vulnerability

A command injection vulnerability exists in the new-interface variable within the cmxddns.lua file of TP-Link WVR, WAR, and ER devices [1]. This affects firmware versions prior to the fix released in January 2018 [1]. The vulnerability requires the device to have the DDNS feature enabled and the attacker to have valid administrative credentials [1].

Exploitation

An attacker with a valid administrator account can send a crafted POST request to the device's web interface, injecting arbitrary operating system commands into the new-interface parameter [1]. No user interaction beyond the authenticated session is required, and the attacker can be on the local network or remotely if the management interface is exposed [1].

Impact

Successful exploitation allows the remote authenticated attacker to execute arbitrary commands on the underlying operating system with root privileges [1]. This results in full compromise of the device's confidentiality, integrity, and availability [1]. The attacker can install persistent backdoors, exfiltrate data, or pivot to other network hosts [1].

Mitigation

TP-Link released firmware updates to address this vulnerability in January 2018 for the affected WVR, WAR, and ER device series [1]. It is recommended to update to the latest firmware from TP-Link's official support site; if upgrading is not possible, administrators should restrict access to the management interface to trusted networks only and disable the DDNS feature if not required [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.