CVE-2017-15615
Description
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the lcpechointerval variable in the pptp_client.lua file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
TP-Link WVR, WAR, ER devices allow authenticated command injection via lcpechointerval in pptp_client.lua, enabling remote code execution.
Vulnerability
Remote authenticated command injection vulnerability in TP-Link WVR, WAR, and ER devices. The lcpechointerval variable in the /usr/lib/lua/luci/controller/admin/pptpd.lua file (referenced as pptp_client.lua in the CVE description) does not sanitize user input, allowing injection of arbitrary commands [1]. The vulnerability affects multiple firmware versions across these device families.
Exploitation
An attacker must have valid administrator credentials to access the web interface. By crafting a malicious value for the lcpechointerval parameter, typically in the PPTP client configuration page, the injected command is executed with root privileges on the device [1].
Impact
Successful exploitation allows remote authenticated attackers to execute arbitrary commands as root, leading to full compromise of the device, including data exfiltration, lateral movement, or use as a botnet node [1].
Mitigation
No official patch has been released by TP-Link as of the publication date. Users should restrict administrative access to trusted networks, change default credentials, and monitor for vendor updates [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/archive/1/541655/100/0/threadedmitremailing-listx_refsource_BUGTRAQ
- github.com/chunibalon/Vulnerability/blob/master/CVE-2017-15613_to_CVE-2017-15637.txtmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.