CVE-2017-15633
Description
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-ipgroup variable in the session_limits.lua file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
TP-Link WVR, WAR, and ER devices allow remote authenticated admins to execute arbitrary commands via command injection in the session_limits.lua new-ipgroup parameter.
Vulnerability
A command injection vulnerability exists in TP-Link WVR, WAR, and ER devices. The flaw resides in the session_limits.lua file, which handles IP group settings. The new-ipgroup variable is not properly sanitized, allowing an authenticated remote administrator to inject arbitrary operating system commands. Affected models include TP-Link WVR, WAR, and ER series routers; specific firmware versions are not enumerated in the available references but the issue was published in January 2018 [1].
Exploitation
The attacker must be a remote authenticated administrator on the TP-Link device. The exploitation involves sending a crafted HTTP request to the device's management interface, injecting shell commands via the new-ipgroup parameter in the session_limits.lua endpoint. No user interaction beyond the attacker's own actions is required [1].
Impact
Successful exploitation grants the attacker arbitrary command execution with root privileges on the device. This leads to full compromise of the router, including the ability to read, modify, or delete all data, intercept network traffic, or use the device as a pivot for further attacks within the network [1].
Mitigation
No official fix or patch from TP-Link was mentioned in the available references. Users should restrict administrative access to trusted networks only, disable remote administration if not needed, and monitor vendor security advisories for any updates. The device may be end-of-life; consulting TP-Link support is recommended [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/archive/1/541655/100/0/threadedmitremailing-listx_refsource_BUGTRAQ
- github.com/chunibalon/Vulnerability/blob/master/CVE-2017-15613_to_CVE-2017-15637.txtmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.