VYPR
Unrated severityNVD Advisory· Published Jan 11, 2018· Updated Aug 5, 2024

CVE-2017-15618

CVE-2017-15618

Description

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-enable variable in the pptp_client.lua file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

TP-Link WVR, WAR, and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in pptp_client.lua.

Vulnerability

A command injection vulnerability exists in the pptp_client.lua file of TP-Link WVR, WAR, and ER series devices. The new-enable variable is vulnerable to injection of arbitrary commands. This affects firmware versions where the file is present. The exact version range is not specified in the available reference [1], but the vulnerability is present in the mentioned device lines.

Exploitation

An attacker must have remote administrative access to the device. By sending a crafted HTTP request that includes malicious commands in the new-enable parameter, the attacker can inject arbitrary operating system commands.

Impact

Successful exploitation allows the authenticated administrator to execute arbitrary commands on the underlying operating system, potentially leading to full compromise of the device, including data exfiltration, modification, or denial of service.

Mitigation

The vendor TP-Link has not explicitly released a fixed firmware version in the provided reference [1]. Users should monitor for firmware updates and apply them when available. If no update exists, consider restricting administrative access to trusted networks only.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.