ID

VAR-201801-0394


CVE

CVE-2017-15613


TITLE

TP-Link WVR, WAR, and ER device arbitrary command execution vulnerability

Trust: 0.6

sources: CNVD: CNVD-2018-01916

DESCRIPTION

TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-interface variable in the cmxddns.lua file. TP-LinkWVR, WAR and ERdevices are different series of router products from China TP-LINK. Security vulnerabilities exist in TP-LinkWVR, WAR, and ER devices

Trust: 5.13

sources: NVD: CVE-2017-15613 // CNVD: CNVD-2018-01916 // CNVD: CNVD-2018-02032 // CNVD: CNVD-2018-02028 // CNVD: CNVD-2018-02027 // CNVD: CNVD-2018-02033 // CNVD: CNVD-2018-02038 // CNVD: CNVD-2018-02037 // VULHUB: VHN-106474 // VULHUB: VHN-106475 // VULHUB: VHN-106453 // VULHUB: VHN-106463 // VULHUB: VHN-106468

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 4.2

sources: CNVD: CNVD-2018-01916 // CNVD: CNVD-2018-02032 // CNVD: CNVD-2018-02028 // CNVD: CNVD-2018-02027 // CNVD: CNVD-2018-02033 // CNVD: CNVD-2018-02038 // CNVD: CNVD-2018-02037

AFFECTED PRODUCTS

vendor:tp linkmodel:erscope: - version: -

Trust: 4.2

vendor:tp linkmodel:wvrscope: - version: -

Trust: 4.2

vendor:tp linkmodel:warscope: - version: -

Trust: 4.2

vendor:tp linkmodel:wvr900lscope:eqversion: -

Trust: 1.6

vendor:tp linkmodel:wvr900gscope:eqversion:3.0_170306

Trust: 1.6

vendor:tp linkmodel:wvr4300lscope:eqversion: -

Trust: 1.6

vendor:tp linkmodel:wvr2600lscope:eqversion: -

Trust: 1.6

vendor:tp linkmodel:wvr450lscope:eqversion:1.0161125

Trust: 1.6

vendor:tp linkmodel:wvr450scope:eqversion: -

Trust: 1.6

vendor:tp linkmodel:wvr300scope:eqversion: -

Trust: 1.6

vendor:tp linkmodel:wvr458lscope:eqversion: -

Trust: 1.6

vendor:tp linkmodel:wvr1750lscope:eqversion: -

Trust: 1.6

vendor:tp linkmodel:wvr302scope:eqversion: -

Trust: 1.6

vendor:tp linkmodel:r473gscope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:r4149gscope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:war1300lscope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:war450lscope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:r4239gscope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:r478\+scope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:war458lscope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:r478scope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:er5120gscope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:r473gp-acscope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:war302scope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:war2600lscope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:r4299gscope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:war1750lscope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:r488scope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:r478g\+scope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:er5110gscope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:r473scope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:war900lscope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:wvr1300gscope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:r473p-acscope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:er5520gscope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:r483gscope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:war458scope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:wvr1300lscope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:r483scope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:war450scope:eqversion: -

Trust: 1.0

vendor:tp linkmodel:er5510gscope:eqversion: -

Trust: 1.0

sources: CNVD: CNVD-2018-01916 // CNVD: CNVD-2018-02032 // CNVD: CNVD-2018-02028 // CNVD: CNVD-2018-02027 // CNVD: CNVD-2018-02033 // CNVD: CNVD-2018-02038 // CNVD: CNVD-2018-02037 // CNNVD: CNNVD-201801-431 // NVD: CVE-2017-15613

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-15613
value: HIGH

Trust: 1.0

CNVD: CNVD-2018-01916
value: HIGH

Trust: 0.6

CNVD: CNVD-2018-02032
value: HIGH

Trust: 0.6

CNVD: CNVD-2018-02028
value: HIGH

Trust: 0.6

CNVD: CNVD-2018-02027
value: HIGH

Trust: 0.6

CNVD: CNVD-2018-02033
value: HIGH

Trust: 0.6

CNVD: CNVD-2018-02038
value: HIGH

Trust: 0.6

CNVD: CNVD-2018-02037
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201801-431
value: HIGH

Trust: 0.6

VULHUB: VHN-106474
value: HIGH

Trust: 0.1

VULHUB: VHN-106475
value: HIGH

Trust: 0.1

VULHUB: VHN-106453
value: HIGH

Trust: 0.1

VULHUB: VHN-106463
value: HIGH

Trust: 0.1

VULHUB: VHN-106468
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2017-15613
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

CNVD: CNVD-2018-01916
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

CNVD: CNVD-2018-02032
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

CNVD: CNVD-2018-02028
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

CNVD: CNVD-2018-02027
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

CNVD: CNVD-2018-02033
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

CNVD: CNVD-2018-02038
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

CNVD: CNVD-2018-02037
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-106474
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

VULHUB: VHN-106475
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

VULHUB: VHN-106453
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

VULHUB: VHN-106463
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

VULHUB: VHN-106468
severity: HIGH
baseScore: 9.0
vectorString: AV:N/AC:L/AU:S/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-15613
baseSeverity: HIGH
baseScore: 7.2
vectorString: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.2
impactScore: 5.9
version: 3.0

Trust: 1.0

sources: CNVD: CNVD-2018-01916 // CNVD: CNVD-2018-02032 // CNVD: CNVD-2018-02028 // CNVD: CNVD-2018-02027 // CNVD: CNVD-2018-02033 // CNVD: CNVD-2018-02038 // CNVD: CNVD-2018-02037 // VULHUB: VHN-106474 // VULHUB: VHN-106475 // VULHUB: VHN-106453 // VULHUB: VHN-106463 // VULHUB: VHN-106468 // CNNVD: CNNVD-201801-431 // NVD: CVE-2017-15613

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:CWE-77

Trust: 0.5

sources: VULHUB: VHN-106474 // VULHUB: VHN-106475 // VULHUB: VHN-106453 // VULHUB: VHN-106463 // VULHUB: VHN-106468 // NVD: CVE-2017-15613

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201801-431

TYPE

command injection

Trust: 0.6

sources: CNNVD: CNNVD-201801-431

PATCH

title:TP-LinkWVR, WAR, and ER device arbitrary command execution vulnerability patchurl:https://www.cnvd.org.cn/patchInfo/show/114425

Trust: 0.6

title:Patch for TP-LinkWVR, WAR, and ER Device Arbitrary Command Execution Vulnerability (CNVD-2018-02032)url:https://www.cnvd.org.cn/patchInfo/show/114575

Trust: 0.6

title:Patch for TP-LinkWVR, WAR, and ER device arbitrary command execution vulnerability (CNVD-2018-02028)url:https://www.cnvd.org.cn/patchInfo/show/114567

Trust: 0.6

title:Patch for TP-LinkWVR, WAR, and ER device arbitrary command execution vulnerability (CNVD-2018-02027)url:https://www.cnvd.org.cn/patchInfo/show/114565

Trust: 0.6

title:Patch for TP-LinkWVR, WAR, and ER device arbitrary command execution vulnerability (CNVD-2018-02033)url:https://www.cnvd.org.cn/patchInfo/show/114577

Trust: 0.6

title:Patch for TP-LinkWVR, WAR, and ER device arbitrary command execution vulnerability (CNVD-2018-02038)url:https://www.cnvd.org.cn/patchInfo/show/114587

Trust: 0.6

title:Patch for TP-LinkWVR, WAR, and ER Device Arbitrary Command Execution Vulnerability (CNVD-2018-02037)url:https://www.cnvd.org.cn/patchInfo/show/114585

Trust: 0.6

title:TP-Link WVR , WAR and ER Repair measures for device security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=77685

Trust: 0.6

sources: CNVD: CNVD-2018-01916 // CNVD: CNVD-2018-02032 // CNVD: CNVD-2018-02028 // CNVD: CNVD-2018-02027 // CNVD: CNVD-2018-02033 // CNVD: CNVD-2018-02038 // CNVD: CNVD-2018-02037 // CNNVD: CNNVD-201801-431

EXTERNAL IDS

db:NVDid:CVE-2017-15613

Trust: 6.3

db:CNNVDid:CNNVD-201801-431

Trust: 0.7

db:CNVDid:CNVD-2018-01916

Trust: 0.6

db:CNVDid:CNVD-2018-02032

Trust: 0.6

db:CNVDid:CNVD-2018-02028

Trust: 0.6

db:CNVDid:CNVD-2018-02027

Trust: 0.6

db:CNVDid:CNVD-2018-02033

Trust: 0.6

db:CNVDid:CNVD-2018-02038

Trust: 0.6

db:CNVDid:CNVD-2018-02037

Trust: 0.6

db:CNNVDid:CNNVD-201710-899

Trust: 0.1

db:VULHUBid:VHN-106474

Trust: 0.1

db:CNNVDid:CNNVD-201710-898

Trust: 0.1

db:VULHUBid:VHN-106475

Trust: 0.1

db:PACKETSTORMid:145823

Trust: 0.1

db:VULHUBid:VHN-106453

Trust: 0.1

db:CNNVDid:CNNVD-201710-909

Trust: 0.1

db:VULHUBid:VHN-106463

Trust: 0.1

db:CNNVDid:CNNVD-201710-904

Trust: 0.1

db:VULHUBid:VHN-106468

Trust: 0.1

sources: CNVD: CNVD-2018-01916 // CNVD: CNVD-2018-02032 // CNVD: CNVD-2018-02028 // CNVD: CNVD-2018-02027 // CNVD: CNVD-2018-02033 // CNVD: CNVD-2018-02038 // CNVD: CNVD-2018-02037 // VULHUB: VHN-106474 // VULHUB: VHN-106475 // VULHUB: VHN-106453 // VULHUB: VHN-106463 // VULHUB: VHN-106468 // CNNVD: CNNVD-201801-431 // NVD: CVE-2017-15613

REFERENCES

url:https://github.com/chunibalon/vulnerability/blob/master/cve-2017-15613_to_cve-2017-15637.txt

Trust: 5.7

url:http://www.securityfocus.com/archive/1/archive/1/541655/100/0/threaded

Trust: 3.6

url:http://www.securityfocus.com/archive/1/541655/100/0/threaded

Trust: 2.1

url:http://seclists.org/bugtraq/2018/jan/31

Trust: 0.6

sources: CNVD: CNVD-2018-01916 // CNVD: CNVD-2018-02032 // CNVD: CNVD-2018-02028 // CNVD: CNVD-2018-02027 // CNVD: CNVD-2018-02033 // CNVD: CNVD-2018-02038 // CNVD: CNVD-2018-02037 // VULHUB: VHN-106474 // VULHUB: VHN-106475 // VULHUB: VHN-106453 // VULHUB: VHN-106463 // VULHUB: VHN-106468 // CNNVD: CNNVD-201801-431 // NVD: CVE-2017-15613

SOURCES

db:CNVDid:CNVD-2018-01916
db:CNVDid:CNVD-2018-02032
db:CNVDid:CNVD-2018-02028
db:CNVDid:CNVD-2018-02027
db:CNVDid:CNVD-2018-02033
db:CNVDid:CNVD-2018-02038
db:CNVDid:CNVD-2018-02037
db:VULHUBid:VHN-106474
db:VULHUBid:VHN-106475
db:VULHUBid:VHN-106453
db:VULHUBid:VHN-106463
db:VULHUBid:VHN-106468
db:CNNVDid:CNNVD-201801-431
db:NVDid:CVE-2017-15613

LAST UPDATE DATE

2025-06-26T23:10:25.197000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-01916date:2018-01-25T00:00:00
db:CNVDid:CNVD-2018-02032date:2018-01-26T00:00:00
db:CNVDid:CNVD-2018-02028date:2018-01-26T00:00:00
db:CNVDid:CNVD-2018-02027date:2018-01-26T00:00:00
db:CNVDid:CNVD-2018-02033date:2018-01-26T00:00:00
db:CNVDid:CNVD-2018-02038date:2018-01-26T00:00:00
db:CNVDid:CNVD-2018-02037date:2018-01-26T00:00:00
db:VULHUBid:VHN-106474date:2019-10-03T00:00:00
db:VULHUBid:VHN-106475date:2019-10-03T00:00:00
db:VULHUBid:VHN-106453date:2019-10-03T00:00:00
db:VULHUBid:VHN-106463date:2019-10-03T00:00:00
db:VULHUBid:VHN-106468date:2019-10-03T00:00:00
db:CNNVDid:CNNVD-201801-431date:2019-10-23T00:00:00
db:NVDid:CVE-2017-15613date:2024-11-21T03:14:51.303

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-01916date:2018-01-12T00:00:00
db:CNVDid:CNVD-2018-02032date:2018-01-26T00:00:00
db:CNVDid:CNVD-2018-02028date:2018-01-26T00:00:00
db:CNVDid:CNVD-2018-02027date:2018-01-26T00:00:00
db:CNVDid:CNVD-2018-02033date:2018-01-12T00:00:00
db:CNVDid:CNVD-2018-02038date:2018-01-12T00:00:00
db:CNVDid:CNVD-2018-02037date:2018-01-12T00:00:00
db:VULHUBid:VHN-106474date:2018-01-11T00:00:00
db:VULHUBid:VHN-106475date:2018-01-11T00:00:00
db:VULHUBid:VHN-106453date:2018-01-11T00:00:00
db:VULHUBid:VHN-106463date:2018-01-11T00:00:00
db:VULHUBid:VHN-106468date:2018-01-11T00:00:00
db:CNNVDid:CNNVD-201801-431date:2018-01-12T00:00:00
db:NVDid:CVE-2017-15613date:2018-01-11T16:29:00.407