VYPR
Unrated severityNVD Advisory· Published Jan 11, 2018· Updated Aug 5, 2024

CVE-2017-15615

CVE-2017-15615

Description

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the lcpechointerval variable in the pptp_client.lua file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

TP-Link WVR, WAR, ER devices allow authenticated command injection via lcpechointerval in pptp_client.lua, enabling remote code execution.

Vulnerability

Remote authenticated command injection vulnerability in TP-Link WVR, WAR, and ER devices. The lcpechointerval variable in the /usr/lib/lua/luci/controller/admin/pptpd.lua file (referenced as pptp_client.lua in the CVE description) does not sanitize user input, allowing injection of arbitrary commands [1]. The vulnerability affects multiple firmware versions across these device families.

Exploitation

An attacker must have valid administrator credentials to access the web interface. By crafting a malicious value for the lcpechointerval parameter, typically in the PPTP client configuration page, the injected command is executed with root privileges on the device [1].

Impact

Successful exploitation allows remote authenticated attackers to execute arbitrary commands as root, leading to full compromise of the device, including data exfiltration, lateral movement, or use as a botnet node [1].

Mitigation

No official patch has been released by TP-Link as of the publication date. Users should restrict administrative access to trusted networks, change default credentials, and monitor for vendor updates [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.