CVE-2017-15628
Description
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the lcpechointerval variable in the pptp_server.lua file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Command injection in TP-Link WVR, WAR, and ER devices allows authenticated remote code execution via the `lcpechointerval` parameter.
Vulnerability
A command injection vulnerability exists in the pptp_server.lua file of TP-Link WVR, WAR, and ER series devices. The lcpechointerval variable, used in the PPTP server configuration, is not sanitized before being passed to a shell command, allowing authenticated administrators to inject arbitrary commands. The flaw affects firmware versions prior to the vendor's security release.
Exploitation
An attacker must have administrative credentials to access the device's management interface. By submitting a crafted value for the lcpechointerval parameter, the attacker can inject shell metacharacters that break out of the intended command and execute arbitrary system commands.
Impact
Successful exploitation grants the attacker remote code execution on the device with root privileges. This can lead to full compromise of the router, enabling further attacks on the local network, data exfiltration, or use of the device in a botnet.
Mitigation
TP-Link has released firmware updates to address this vulnerability. Affected users should upgrade to the latest firmware for their specific device model as indicated in the vendor advisory [1]. No known workaround exists; however, access to the management interface should be restricted to trusted administrators as a defense-in-depth measure.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/archive/1/541655/100/0/threadedmitremailing-listx_refsource_BUGTRAQ
- github.com/chunibalon/Vulnerability/blob/master/CVE-2017-15613_to_CVE-2017-15637.txtmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.