9
CVSSv2

CVE-2017-17758

Published: 19/12/2017 Updated: 03/10/2019
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/dhcps command to cgi-bin/luci, related to the zone_get_iface_bydev function in /usr/lib/lua/luci/controller/admin/dhcps.lua in uhttpd.

Vulnerable Product Search on Vulmon Subscribe to Product

tp-link tl-wvr450l_firmware -

tp-link tl-wvr458l_firmware -

tp-link tl-wvr900l_firmware -

tp-link tl-wvr1200l_firmware -

tp-link tl-wvr1300l_firmware -

tp-link tl-wvr1750l_firmware -

tp-link tl-wvr2600l_firmware -

tp-link tl-wvr4300l_firmware -

tp-link tl-war450l_firmware -

tp-link tl-war458l_firmware -

tp-link tl-war900l_firmware -

tp-link tl-war1200l_firmware -

tp-link tl-war1300l_firmware -

tp-link tl-war1750l_firmware -

tp-link tl-war2600l_firmware -