ID

VAR-E-201712-0467


CVE

cve_id:CVE-2017-17758

Trust: 0.3

sources: BID: 102259

TITLE

Multiple TP-Link Devices CVE-2017-17758 Arbitrary Command Execution Vulnerability

Trust: 0.3

sources: BID: 102259

DESCRIPTION

Multiple TP-Link Devices are prone to a remote arbitrary command-execution vulnerability.
An attacker can exploit this issue to execute arbitrary commands in context of the affected application.

Trust: 0.3

sources: BID: 102259

AFFECTED PRODUCTS

vendor:tp linkmodel:tl-wvr900gscope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-wvr458pscope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-wvr458lscope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-wvr458scope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-wvr450lscope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-wvr450gscope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-wvr450scope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-wvr4300lscope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-wvr302scope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-wvr300scope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-wvr2600lscope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-wvr1750lscope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-wvr1300lscope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-wvr1300gscope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-wvr1200lscope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-war900lscope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-war458lscope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-war458scope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-war450lscope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-war450scope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-war302scope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-war2600lscope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-war1750lscope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-war1300lscope:eqversion:0

Trust: 0.3

vendor:tp linkmodel:tl-war1200lscope:eqversion:0

Trust: 0.3

sources: BID: 102259

EXPLOIT

The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.

Trust: 0.3

sources: BID: 102259

PRICE

Free

Trust: 0.3

sources: BID: 102259

TYPE

Input Validation Error

Trust: 0.3

sources: BID: 102259

CREDITS

Zhaoxin Li, Chengdu Tongjin Middle School.

Trust: 0.3

sources: BID: 102259

EXTERNAL IDS

db:NVDid:CVE-2017-17758

Trust: 0.3

db:BIDid:102259

Trust: 0.3

sources: BID: 102259

REFERENCES

url:https://github.com/l1zhaoxin/router-vulnerability-research/blob/master/tplink_luci_dhcps_authenticated_rce_record.txt

Trust: 0.3

url:http://www.tp-link.com/en/

Trust: 0.3

sources: BID: 102259

SOURCES

db:BIDid:102259

LAST UPDATE DATE

2022-07-27T09:32:20.941000+00:00


SOURCES UPDATE DATE

db:BIDid:102259date:2017-12-19T00:00:00

SOURCES RELEASE DATE

db:BIDid:102259date:2017-12-19T00:00:00