CVE-2017-15634

HIGH

Tp-link Er5110g Firmware - Command Injection

Title source: rule

Description

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the name variable in the wportal.lua file.

Scores

CVSS v3 7.2
EPSS 0.0139
EPSS Percentile 80.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Classification

Status published

Affected Products (38)

tp-link/er5110g_firmware
tp-link/er5120g_firmware
tp-link/er5510g_firmware
tp-link/er5520g_firmware
tp-link/r4149g_firmware
tp-link/r4239g_firmware
tp-link/r4299g_firmware
tp-link/r473gp-ac_firmware
tp-link/r473g_firmware
tp-link/r473p-ac_firmware
tp-link/r473_firmware
tp-link/r478g\+_firmware
tp-link/r478_firmware
tp-link/r478\+_firmware
tp-link/r483g_firmware
... and 23 more

Timeline

Published Jan 11, 2018
Tracked Since Feb 18, 2026