9

CVE-2017-15634

Exploit

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the name variable in the wportal.lua file.

Data is provided by the National Vulnerability Database (NVD)
Tp-linkEr5110g Firmware Version-
   Tp-linkEr5110g Version-
Tp-linkEr5120g Firmware Version-
   Tp-linkEr5120g Version-
Tp-linkEr5510g Firmware Version-
   Tp-linkEr5510g Version-
Tp-linkEr5520g Firmware Version-
   Tp-linkEr5520g Version-
Tp-linkR4149g Firmware Version-
   Tp-linkR4149g Version-
Tp-linkR4239g Firmware Version-
   Tp-linkR4239g Version-
Tp-linkR4299g Firmware Version-
   Tp-linkR4299g Version-
Tp-linkR473gp-ac Firmware Version-
   Tp-linkR473gp-ac Version-
Tp-linkR473g Firmware Version-
   Tp-linkR473g Version-
Tp-linkR473p-ac Firmware Version-
   Tp-linkR473p-ac Version-
Tp-linkR473 Firmware Version-
   Tp-linkR473 Version-
Tp-linkR478g+ Firmware Version-
   Tp-linkR478g+ Version-
Tp-linkR478 Firmware Version-
   Tp-linkR478 Version-
Tp-linkR478+ Firmware Version-
   Tp-linkR478+ Version-
Tp-linkR483g Firmware Version-
   Tp-linkR483g Version-
Tp-linkR483 Firmware Version-
   Tp-linkR483 Version-
Tp-linkR488 Firmware Version-
   Tp-linkR488 Version-
Tp-linkWar1300l Firmware Version-
   Tp-linkWar1300l Version-
Tp-linkWar1750l Firmware Version-
   Tp-linkWar1750l Version-
Tp-linkWar2600l Firmware Version-
   Tp-linkWar2600l Version-
Tp-linkWar302 Firmware Version-
   Tp-linkWar302 Version-
Tp-linkWar450l Firmware Version-
   Tp-linkWar450l Version-
Tp-linkWar450 Firmware Version-
   Tp-linkWar450 Version-
Tp-linkWar458l Firmware Version-
   Tp-linkWar458l Version-
Tp-linkWar458 Firmware Version-
   Tp-linkWar458 Version-
Tp-linkWar900l Firmware Version-
   Tp-linkWar900l Version-
Tp-linkWvr1300g Firmware Version-
   Tp-linkWvr1300g Version-
Tp-linkWvr1300l Firmware Version-
   Tp-linkWvr1300l Version-
Tp-linkWvr1750l Firmware Version-
   Tp-linkWvr1750l Version-
Tp-linkWvr2600l Firmware Version-
   Tp-linkWvr2600l Version-
Tp-linkWvr300 Firmware Version-
   Tp-linkWvr300 Version-
Tp-linkWvr302 Firmware Version-
   Tp-linkWvr302 Version-
Tp-linkWvr4300l Firmware Version-
   Tp-linkWvr4300l Version-
Tp-linkWvr450l Firmware Version1.0161125
   Tp-linkWvr450l Version-
Tp-linkWvr450 Firmware Version-
   Tp-linkWvr450 Version-
Tp-linkWvr458l Firmware Version-
   Tp-linkWvr458l Version-
Tp-linkWvr900g Firmware Version3.0_170306
   Tp-linkWvr900g Version-
Tp-linkWvr900l Firmware Version-
   Tp-linkWvr900l Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.39% 0.795
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C