CVE-2017-15634
HIGHTp-link Er5110g Firmware - Command Injection
Title source: ruleDescription
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the name variable in the wportal.lua file.
Scores
CVSS v3
7.2
EPSS
0.0139
EPSS Percentile
80.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Classification
Status
published
Affected Products (38)
tp-link/er5110g_firmware
tp-link/er5120g_firmware
tp-link/er5510g_firmware
tp-link/er5520g_firmware
tp-link/r4149g_firmware
tp-link/r4239g_firmware
tp-link/r4299g_firmware
tp-link/r473gp-ac_firmware
tp-link/r473g_firmware
tp-link/r473p-ac_firmware
tp-link/r473_firmware
tp-link/r478g\+_firmware
tp-link/r478_firmware
tp-link/r478\+_firmware
tp-link/r483g_firmware
... and 23 more
Timeline
Published
Jan 11, 2018
Tracked Since
Feb 18, 2026