CVE-2017-16960
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/interface.lua in uhttpd.
Affected (58)
Products: Tp Link: Tl Er5510g, Tl Er5520g, Tl Er6120g, Tl Er6520g, Tl R4239g, Tl R4299g, Tl R473, Tl R478+, Tl R478g+, Tl R483, Tl R483g, Tl R488, Tl Wvr300, Tl Wvr302, Tl Wvr450g, Tl Wvr900g, Tl Wvr450 Firmware, Tl Wvr450l Firmware, Tl Wvr458 Firmware, Tl Wvr458l Firmware, Tl Wvr458p Firmware, Tl Wvr900l Firmware, Tl Wvr1200l Firmware, Tl Wvr1300l Firmware, Tl Wvr1300g Firmware, Tl Wvr1750l Firmware, Tl Wvr2600l Firmware, Tl Wvr4300l Firmware, Tl War302 Firmware, Tl War450 Firmware, Tl War450l Firmware, Tl War458 Firmware, Tl War458l Firmware, Tl War900l Firmware, Tl War1200l Firmware, Tl War1300l Firmware, Tl War1750l Firmware, Tl War2600l Firmware, Tl Er3210g Firmware, Tl Er3220g Firmware, Tl Er5110g Firmware, Tl Er5120g Firmware, Tl Er6110g Firmware, Tl Er6220g Firmware, Tl Er6510g Firmware, Tl Er7520g Firmware, Tl R473g Firmware, Tl R473p Ac Firmware, Tl R473gp Ac Firmware, Tl R478g Firmware, Tl R479p Ac Firmware, Tl R479gp Ac Firmware, Tl R479gpe Ac Firmware, Tl R4149g Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version v2 | |
| Version v2 | |
| Version v2 | |
| Version v2 | |
| Version v2 | |
| Version v2 | |
| Version v5 | |
| Version v6 | |
| Version v7 | |
| Version v3 | |
| Version v5 | |
| Version v2 | |
| Version v5 | |
| Version v4 | |
| Version v2 | |
| Version v5 | |
| Version v3 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Wvr450 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Wvr450l | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Wvr458 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Wvr458l | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Wvr458p | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Wvr900l | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Wvr1200l | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Wvr1300l | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Wvr1300g | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Wvr1750l | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Wvr2600l | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Wvr4300l | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl War302 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl War450 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl War450l | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl War458 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl War458l | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl War900l | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl War1200l | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl War1300l | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl War1750l | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl War2600l | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Er3210g | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Er3220g | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Er5110g | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Er5120g | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Er6110g | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Er6220g | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Er6510g | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl Er7520g | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl R473g | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl R473p Ac | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl R473gp Ac | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl R478g | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl R479p Ac | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl R479gp Ac | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl R479gpe Ac | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tl R4149g | All versions |
References (2)
Source: cve@mitre.org
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Timeline
No history available yet.