Description
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/interface.lua in uhttpd.
Published: 2017-11-27
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2017-8129 TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/interface.lua in uhttpd.
History

No history.

Subscriptions

Tp-link Tl-er3210g Tl-er3210g Firmware Tl-er3220g Tl-er3220g Firmware Tl-er5110g Tl-er5110g Firmware Tl-er5120g Tl-er5120g Firmware Tl-er5510g Tl-er5520g Tl-er6110g Tl-er6110g Firmware Tl-er6120g Tl-er6220g Tl-er6220g Firmware Tl-er6510g Tl-er6510g Firmware Tl-er6520g Tl-er7520g Tl-er7520g Firmware Tl-r4149g Tl-r4149g Firmware Tl-r4239g Tl-r4299g Tl-r473 Tl-r473g Tl-r473g Firmware Tl-r473gp-ac Tl-r473gp-ac Firmware Tl-r473p-ac Tl-r473p-ac Firmware Tl-r478 Tl-r478\+ Tl-r478g Tl-r478g\+ Tl-r478g Firmware Tl-r479gp-ac Tl-r479gp-ac Firmware Tl-r479gpe-ac Tl-r479gpe-ac Firmware Tl-r479p-ac Tl-r479p-ac Firmware Tl-r483 Tl-r483g Tl-r488 Tl-war1200l Tl-war1200l Firmware Tl-war1300l Tl-war1300l Firmware Tl-war1750l Tl-war1750l Firmware Tl-war2600l Tl-war2600l Firmware Tl-war302 Tl-war302 Firmware Tl-war450 Tl-war450 Firmware Tl-war450l Tl-war450l Firmware Tl-war458 Tl-war458 Firmware Tl-war458l Tl-war458l Firmware Tl-war900l Tl-war900l Firmware Tl-wvr1200l Tl-wvr1200l Firmware Tl-wvr1300g Tl-wvr1300g Firmware Tl-wvr1300l Tl-wvr1300l Firmware Tl-wvr1750l Tl-wvr1750l Firmware Tl-wvr2600l Tl-wvr2600l Firmware Tl-wvr300 Tl-wvr302 Tl-wvr4300l Tl-wvr4300l Firmware Tl-wvr450 Tl-wvr450 Firmware Tl-wvr450g Tl-wvr450l Tl-wvr450l Firmware Tl-wvr458 Tl-wvr458 Firmware Tl-wvr458l Tl-wvr458l Firmware Tl-wvr458p Tl-wvr458p Firmware Tl-wvr900g Tl-wvr900l Tl-wvr900l Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T20:43:59.342Z

Reserved: 2017-11-27T00:00:00.000Z

Link: CVE-2017-16960

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-11-27T10:29:00.547

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-16960

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses