VYPR
Unrated severityNVD Advisory· Published Jan 11, 2018· Updated Aug 5, 2024

CVE-2017-15622

CVE-2017-15622

Description

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-mppeencryption variable in the pptp_client.lua file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

TP-Link WVR/WAR/ER devices allow authenticated admin command injection via new-mppeencryption in pptp_client.lua, enabling remote code execution.

Vulnerability

The vulnerability is a command injection flaw in the pptp_client.lua file on TP-Link WVR, WAR, and ER series devices. The new-mppeencryption variable is not properly sanitized before being used in a command execution context, allowing an authenticated administrator to inject arbitrary operating system commands. Affected firmware versions include all releases prior to the vendor's patch. [1]

Exploitation

An attacker must have valid administrative credentials to the device's web interface. By sending a crafted HTTP request to the endpoint that processes the pptp_client.lua script, the attacker can inject commands via the new-mppeencryption parameter. The injected commands are executed with the privileges of the web server, typically root. [1]

Impact

Successful exploitation allows a remote authenticated administrator to execute arbitrary commands on the underlying operating system. This can lead to full device compromise, including data exfiltration, installation of persistent backdoors, lateral movement within the network, and disruption of device services. [1]

Mitigation

No specific mitigation details are provided in the available references. Users should restrict administrative access to trusted networks only, use strong passwords, and monitor the vendor's support page for firmware updates that address this vulnerability. [1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.