CVE-2017-15631

UnknownEPSS 4.37%

Last modified

CVE-2017-15631 is a vulnerability of currently unknown severity. TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-workmode variable in the pptp_client.lua file.. EPSS estimates a 4.37% chance of exploitation in the next 30 days.

Description

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-workmode variable in the pptp_client.lua file.

Metrics

EPSS Probability
4.37%

90.0th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
Tp-LinkEr5110g FirmwareAll versions
Tp-LinkEr5120g FirmwareAll versions
Tp-LinkEr5510g FirmwareAll versions
Tp-LinkEr5520g FirmwareAll versions
Tp-LinkR4149g FirmwareAll versions
Tp-LinkR4239g FirmwareAll versions
Tp-LinkR4299g FirmwareAll versions
Tp-LinkR473gp-Ac FirmwareAll versions
Tp-LinkR473g FirmwareAll versions
Tp-LinkR473p-Ac FirmwareAll versions
Tp-LinkR473 FirmwareAll versions
Tp-LinkR478g\+ FirmwareAll versions
Tp-LinkR478 FirmwareAll versions
Tp-LinkR478\+ FirmwareAll versions
Tp-LinkR483g FirmwareAll versions
Tp-LinkR483 FirmwareAll versions
Tp-LinkR488 FirmwareAll versions
Tp-LinkWar1300l FirmwareAll versions
Tp-LinkWar1750l FirmwareAll versions
Tp-LinkWar2600l FirmwareAll versions
Tp-LinkWar302 FirmwareAll versions
Tp-LinkWar450l FirmwareAll versions
Tp-LinkWar450 FirmwareAll versions
Tp-LinkWar458l FirmwareAll versions
Tp-LinkWar458 FirmwareAll versions
Tp-LinkWar900l FirmwareAll versions
Tp-LinkWvr1300g FirmwareAll versions
Tp-LinkWvr1300l FirmwareAll versions
Tp-LinkWvr1750l FirmwareAll versions
Tp-LinkWvr2600l FirmwareAll versions
Tp-LinkWvr300 FirmwareAll versions
Tp-LinkWvr302 FirmwareAll versions
Tp-LinkWvr4300l FirmwareAll versions
Tp-LinkWvr450l Firmware1.0161125
Tp-LinkWvr450 FirmwareAll versions
Tp-LinkWvr458l FirmwareAll versions
Tp-LinkWvr900g Firmware3.0_170306
Tp-LinkWvr900l FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-15631?
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-workmode variable in the pptp_client.lua file.
How severe is CVE-2017-15631?
Severity scoring for CVE-2017-15631 is pending analysis. The EPSS model estimates a 4.37% probability of exploitation in the next 30 days.
How do I fix CVE-2017-15631?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-15631?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST