TROYANOSYVIRUS
Back to CVEs

CVE-2017-15613

N/A

Description

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-interface variable in the cmxddns.lua file.

CVE Details

CVSS v3.1 ScoreN/A
Published1/11/2018
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

tp-link:er5110gtp-link:er5110g_firmwaretp-link:er5120gtp-link:er5120g_firmwaretp-link:er5510gtp-link:er5510g_firmwaretp-link:er5520gtp-link:er5520g_firmwaretp-link:r4149gtp-link:r4149g_firmwaretp-link:r4239gtp-link:r4239g_firmwaretp-link:r4299gtp-link:r4299g_firmwaretp-link:r473tp-link:r473_firmwaretp-link:r473gtp-link:r473g_firmwaretp-link:r473gp-actp-link:r473gp-ac_firmwaretp-link:r473p-actp-link:r473p-ac_firmwaretp-link:r478tp-link:r478\+tp-link:r478\+_firmwaretp-link:r478_firmwaretp-link:r478g\+tp-link:r478g\+_firmwaretp-link:r483tp-link:r483_firmwaretp-link:r483gtp-link:r483g_firmwaretp-link:r488tp-link:r488_firmwaretp-link:war1300ltp-link:war1300l_firmwaretp-link:war1750ltp-link:war1750l_firmwaretp-link:war2600ltp-link:war2600l_firmwaretp-link:war302tp-link:war302_firmwaretp-link:war450tp-link:war450_firmwaretp-link:war450ltp-link:war450l_firmwaretp-link:war458tp-link:war458_firmwaretp-link:war458ltp-link:war458l_firmwaretp-link:war900ltp-link:war900l_firmwaretp-link:wvr1300gtp-link:wvr1300g_firmwaretp-link:wvr1300ltp-link:wvr1300l_firmwaretp-link:wvr1750ltp-link:wvr1750l_firmwaretp-link:wvr2600ltp-link:wvr2600l_firmwaretp-link:wvr300tp-link:wvr300_firmwaretp-link:wvr302tp-link:wvr302_firmwaretp-link:wvr4300ltp-link:wvr4300l_firmwaretp-link:wvr450tp-link:wvr450_firmwaretp-link:wvr450ltp-link:wvr450l_firmwaretp-link:wvr458ltp-link:wvr458l_firmwaretp-link:wvr900gtp-link:wvr900g_firmwaretp-link:wvr900ltp-link:wvr900l_firmware

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.