RSS   Vulnerabilities for 'Er5120g firmware'   RSS

2018-01-11
 
CVE-2017-15637

CWE-77
 

 
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the pptphellointerval variable in the pptp_server.lua file.

 
 
CVE-2017-15636

CWE-77
 

 
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-time variable in the webfilter.lua file.

 
 
CVE-2017-15635

CWE-77
 

 
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the max_conn variable in the session_limits.lua file.

 
 
CVE-2017-15634

CWE-77
 

 
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the name variable in the wportal.lua file.

 
 
CVE-2017-15633

CWE-77
 

 
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-ipgroup variable in the session_limits.lua file.

 
 
CVE-2017-15632

CWE-77
 

 
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-mppeencryption variable in the pptp_server.lua file.

 
 
CVE-2017-15631

CWE-77
 

 
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-workmode variable in the pptp_client.lua file.

 
 
CVE-2017-15630

CWE-77
 

 
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-remotesubnet variable in the pptp_client.lua file.

 
 
CVE-2017-15629

CWE-77
 

 
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-tunnelname variable in the pptp_client.lua file.

 
 
CVE-2017-15628

CWE-77
 

 
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the lcpechointerval variable in the pptp_server.lua file.

 


Copyright 2019, cxsecurity.com

 

Back to Top