Tp Link · Tp-Link War · CVE-2017-15637
Name of the Vulnerable Software and Affected Versions:
TP-Link WVR, WAR and ER devices (affected versions not specified)
Description:
The issue allows remote authenticated administrators to execute arbitrary commands via command injection in the `pptphellointerval` variable in the pptp server.lua file.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.