Lucene search

K
cve[email protected]CVE-2017-16960
HistoryNov 27, 2017 - 10:29 a.m.

CVE-2017-16960

2017-11-2710:29:00
CWE-78
web.nvd.nist.gov
25
tp-link
remote command execution
cve-2017-16960
security vulnerability
nvd
t_bindif
cgi-bin
lua
uhttpd

9 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.7%

TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/interface.lua in uhttpd.

Affected configurations

NVD
Node
tp-linktl-er5510gMatchv2
OR
tp-linktl-er5510gMatchv3
OR
tp-linktl-er5520gMatchv2
OR
tp-linktl-er5520gMatchv3
OR
tp-linktl-er6120gMatchv2
OR
tp-linktl-er6520gMatchv2
OR
tp-linktl-er6520gMatchv3
OR
tp-linktl-r4239gMatchv2
OR
tp-linktl-r4299gMatchv2
OR
tp-linktl-r473Matchv5
OR
tp-linktl-r478Matchv6
OR
tp-linktl-r478\+Matchv7
OR
tp-linktl-r478g\+Matchv3
OR
tp-linktl-r483Matchv5
OR
tp-linktl-r483gMatchv2
OR
tp-linktl-r488Matchv5
OR
tp-linktl-wvr300Matchv4
OR
tp-linktl-wvr302Matchv2
OR
tp-linktl-wvr450gMatchv5
OR
tp-linktl-wvr900gMatchv3
Node
tp-linktl-wvr450_firmwareMatch-
AND
tp-linktl-wvr450Match-
Node
tp-linktl-wvr450l_firmwareMatch-
AND
tp-linktl-wvr450lMatch-
Node
tp-linktl-wvr458_firmwareMatch-
AND
tp-linktl-wvr458Match-
Node
tp-linktl-wvr458l_firmwareMatch-
AND
tp-linktl-wvr458lMatch-
Node
tp-linktl-wvr458p_firmwareMatch-
AND
tp-linktl-wvr458p
Node
tp-linktl-wvr900l_firmwareMatch-
AND
tp-linktl-wvr900lMatch-
Node
tp-linktl-wvr1200l_firmwareMatch-
AND
tp-linktl-wvr1200lMatch-
Node
tp-linktl-wvr1300l_firmwareMatch-
AND
tp-linktl-wvr1300lMatch-
Node
tp-linktl-wvr1300g_firmwareMatch-
AND
tp-linktl-wvr1300gMatch-
Node
tp-linktl-wvr1750l_firmwareMatch-
AND
tp-linktl-wvr1750lMatch-
Node
tp-linktl-wvr2600l_firmwareMatch-
AND
tp-linktl-wvr2600lMatch-
Node
tp-linktl-wvr4300l_firmwareMatch-
AND
tp-linktl-wvr4300lMatch-
Node
tp-linktl-war302_firmwareMatch-
AND
tp-linktl-war302Match-
Node
tp-linktl-war450_firmwareMatch-
AND
tp-linktl-war450Match-
Node
tp-linktl-war450l_firmwareMatch-
AND
tp-linktl-war450lMatch-
Node
tp-linktl-war458_firmwareMatch-
AND
tp-linktl-war458Match-
Node
tp-linktl-war458l_firmwareMatch-
AND
tp-linktl-war458lMatch-
Node
tp-linktl-war900l_firmwareMatch-
AND
tp-linktl-war900lMatch-
Node
tp-linktl-war1200l_firmwareMatch-
AND
tp-linktl-war1200lMatch-
Node
tp-linktl-war1300l_firmwareMatch-
AND
tp-linktl-war1300lMatch-
Node
tp-linktl-war1750l_firmwareMatch-
AND
tp-linktl-war1750lMatch-
Node
tp-linktl-war2600l_firmwareMatch-
AND
tp-linktl-war2600lMatch-
Node
tp-linktl-er3210g_firmwareMatch-
AND
tp-linktl-er3210gMatch-
Node
tp-linktl-er3220g_firmware
AND
tp-linktl-er3220gMatch-
Node
tp-linktl-er5110g_firmwareMatch-
AND
tp-linktl-er5110gMatch-
Node
tp-linktl-er5120g_firmwareMatch-
AND
tp-linktl-er5120gMatch-
Node
tp-linktl-er6110g_firmwareMatch-
AND
tp-linktl-er6110gMatch-
Node
tp-linktl-er6220g_firmwareMatch-
AND
tp-linktl-er6220gMatch-
Node
tp-linktl-er6510g_firmwareMatch-
AND
tp-linktl-er6510gMatch-
Node
tp-linktl-er7520g_firmwareMatch-
AND
tp-linktl-er7520gMatch-
Node
tp-linktl-r473g_firmwareMatch-
AND
tp-linktl-r473gMatch-
Node
tp-linktl-r473p-ac_firmwareMatch-
AND
tp-linktl-r473p-acMatch-
Node
tp-linktl-r473gp-ac_firmwareMatch-
AND
tp-linktl-r473gp-acMatch-
Node
tp-linktl-r478g_firmwareMatch-
AND
tp-linktl-r478gMatch-
Node
tp-linktl-r478g_firmwareMatch-
AND
tp-linktl-r478gMatch-
Node
tp-linktl-r479p-ac_firmwareMatch-
AND
tp-linktl-r479p-acMatch-
Node
tp-linktl-r479gp-ac_firmwareMatch-
AND
tp-linktl-r479gp-acMatch-
Node
tp-linktl-r479gpe-ac_firmwareMatch-
AND
tp-linktl-r479gpe-acMatch-
Node
tp-linktl-r4149g_firmwareMatch-
AND
tp-linktl-r4149gMatch-

9 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

48.7%

Related for CVE-2017-16960