VYPR
Unrated severityNVD Advisory· Published Jan 11, 2018· Updated Aug 5, 2024

CVE-2017-15635

CVE-2017-15635

Description

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the max_conn variable in the session_limits.lua file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

TP-Link WVR, WAR, and ER devices are vulnerable to authenticated command injection via the max_conn parameter in session_limits.lua.

Vulnerability

TP-Link WVR, WAR, and ER series routers contain a command injection vulnerability in the session_limits.lua file. The max_conn variable is not properly sanitized, allowing remote authenticated administrators to inject arbitrary OS commands [1]. Affected versions include firmware releases for these series prior to the patched versions (specific versions not disclosed in the available reference).

Exploitation

An attacker with valid administrative credentials can exploit this vulnerability by sending a crafted HTTP POST request to the session_limits.lua endpoint with a malicious max_conn parameter containing shell metacharacters (e.g., ; or backticks). The injected command is then executed on the device with root privileges [1].

Impact

Successful exploitation allows an authenticated administrator to execute arbitrary commands on the underlying operating system, leading to full compromise of the device. This could result in unauthorized access to network traffic, modification of device configuration, or use as a pivot for further attacks [1].

Mitigation

No official patch has been confirmed in the available references. Users should restrict administrative access to trusted networks and monitor for firmware updates from TP-Link. As a workaround, disable remote administration if not required [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.