CVE-2017-15631
Description
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-workmode variable in the pptp_client.lua file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
TP-Link WVR, WAR, and ER devices are vulnerable to command injection via the new-workmode variable in pptp_client.lua, allowing authenticated admins to execute arbitrary commands.
Vulnerability
TP-Link WVR, WAR, and ER series routers contain a command injection vulnerability in the new-workmode parameter within the pptp_client.lua file. This allows remote authenticated administrators to inject arbitrary operating system commands. The vulnerability affects devices running firmware versions prior to the fix released in [1]. The new-workmode variable is not properly sanitized, enabling injection of shell commands.
Exploitation
An attacker needs remote authenticated administrative access to the device. The attacker can send a crafted HTTP request to the vulnerable endpoint with malicious input in the new-workmode parameter. The command injection occurs when the device processes the parameter, executing the injected commands with root privileges. No user interaction is required beyond authentication.
Impact
Successful exploitation allows the attacker to execute arbitrary commands on the device with root privileges. This can lead to full compromise of the device, including data exfiltration, installation of malware, or further network attacks. The impact is high as it provides complete control over the router.
Mitigation
TP-Link has released firmware updates to address this vulnerability. Users should update to the latest firmware version for their specific device model. If no update is available, restrict administrative access to trusted networks only. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog as of the publication date. [1] provides a list of affected models and further details.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/archive/1/541655/100/0/threadedmitremailing-listx_refsource_BUGTRAQ
- github.com/chunibalon/Vulnerability/blob/master/CVE-2017-15613_to_CVE-2017-15637.txtmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.