CVE-2017-17758
Last modified
CVE-2017-17758 is a vulnerability of currently unknown severity. TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/dhcps command to cgi-bin/luci, related to the zone_get_iface_bydev function in /usr/lib/lua/luci/controller/admin/dhcps.lua in uhttpd.. EPSS estimates a 2.64% chance of exploitation in the next 30 days.
Description
TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/dhcps command to cgi-bin/luci, related to the zone_get_iface_bydev function in /usr/lib/lua/luci/controller/admin/dhcps.lua in uhttpd.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Tl-Wvr450l Firmware | All versions |
| Tp-Link | Tl-Wvr458l Firmware | All versions |
| Tp-Link | Tl-Wvr900l Firmware | All versions |
| Tp-Link | Tl-Wvr1200l Firmware | All versions |
| Tp-Link | Tl-Wvr1300l Firmware | All versions |
| Tp-Link | Tl-Wvr1750l Firmware | All versions |
| Tp-Link | Tl-Wvr2600l Firmware | All versions |
| Tp-Link | Tl-Wvr4300l Firmware | All versions |
| Tp-Link | Tl-War450l Firmware | All versions |
| Tp-Link | Tl-War458l Firmware | All versions |
| Tp-Link | Tl-War900l Firmware | All versions |
| Tp-Link | Tl-War1200l Firmware | All versions |
| Tp-Link | Tl-War1300l Firmware | All versions |
| Tp-Link | Tl-War1750l Firmware | All versions |
| Tp-Link | Tl-War2600l Firmware | All versions |
References
- https://github.com/L1ZhaoXin/Router-Vulnerability-Research/blob/master/Tplink_LUCI_Dhcps_Authenticated_RCE_Record.txtExploit, Issue Tracking, Third Party Advisory
- https://github.com/L1ZhaoXin/Router-Vulnerability-Research/blob/master/Tplink_LUCI_Dhcps_Authenticated_RCE_Record.txtExploit, Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-17758?
How severe is CVE-2017-17758?
How do I fix CVE-2017-17758?
Are you affected by CVE-2017-17758?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
