Description
TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/wportal command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/wportal.lua in uhttpd.
Published: 2017-12-19
Score: 8.8 High
EPSS: 1.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2017-8909 TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/wportal command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/wportal.lua in uhttpd.
History

No history.

Subscriptions

Tp-link Tl-war1200l Tl-war1200l Firmware Tl-war1300l Tl-war1300l Firmware Tl-war1750l Tl-war1750l Firmware Tl-war2600l Tl-war2600l Firmware Tl-war450l Tl-war450l Firmware Tl-war458l Tl-war458l Firmware Tl-war900l Tl-war900l Firmware Tl-wvr1200l Tl-wvr1200l Firmware Tl-wvr1300l Tl-wvr1300l Firmware Tl-wvr1750l Tl-wvr1750l Firmware Tl-wvr2600l Tl-wvr2600l Firmware Tl-wvr4300l Tl-wvr4300l Firmware Tl-wvr450l Tl-wvr450l Firmware Tl-wvr458l Tl-wvr458l Firmware Tl-wvr900l Tl-wvr900l Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T20:59:17.960Z

Reserved: 2017-12-19T00:00:00.000Z

Link: CVE-2017-17757

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-12-19T07:29:00.200

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-17757

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses