Description
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/bridge command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/bridge.lua in uhttpd.
Published: 2017-11-27
Score: 8.8 High
EPSS: 1.4% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2017-8127 TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/bridge command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/bridge.lua in uhttpd.
History

No history.

Subscriptions

Tp-link Tl-er3210g Tl-er3210g Firmware Tl-er3220g Tl-er3220g Firmware Tl-er5110g Tl-er5110g Firmware Tl-er5120g Tl-er5120g Firmware Tl-er5510g Tl-er5510g Firmware Tl-er5520g Tl-er5520g Firmware Tl-er6110g Tl-er6110g Firmware Tl-er6120g Tl-er6120g Firmware Tl-er6220g Tl-er6220g Firmware Tl-er6510g Tl-er6510g Firmware Tl-er6520g Tl-er6520g Firmware Tl-er7520g Tl-er7520g Firmware Tl-r4149g Tl-r4149g Firmware Tl-r4239g Tl-r4239g Firmware Tl-r4299g Tl-r4299g Firmware Tl-r473 Tl-r473 Firmware Tl-r473g Tl-r473g Firmware Tl-r473gp-ac Tl-r473p-ac Tl-r473p-ac Firmware Tl-r478 Tl-r478\+ Tl-r478\+ Firmware Tl-r478 Firmware Tl-r478g Tl-r478g\+ Tl-r478g\+ Firmware Tl-r478g Firmware Tl-r479gp-ac Tl-r479gp-ac Firmware Tl-r479gpe-ac Tl-r479gpe-ac Firmware Tl-r479p-ac Tl-r479p-ac Firmware Tl-r483 Tl-r483 Firmware Tl-r483g Tl-r483g Firmware Tl-r488 Tl-r488 Firmware Tl-war1200l Tl-war1200l Firmware Tl-war1300g Tl-war1300l Tl-war1300l Firmware Tl-war1750l Tl-war1750l Firmware Tl-war2600l Tl-war2600l Firmware Tl-war302 Tl-war302 Firmware Tl-war450 Tl-war450 Firmware Tl-war450l Tl-war450l Firmware Tl-war458 Tl-war458 Firmware Tl-war458l Tl-war458l Firmware Tl-war900l Tl-war900l Firmware Tl-wvr1200l Tl-wvr1200l Firmware Tl-wvr1300g Firmware Tl-wvr1300l Tl-wvr1300l Firmware Tl-wvr1750l Tl-wvr1750l Firmware Tl-wvr2600l Tl-wvr300 Tl-wvr300 Firmware Tl-wvr302 Tl-wvr302 Firmware Tl-wvr4300l Tl-wvr4300l Firmware Tl-wvr450 Tl-wvr450 Firmware Tl-wvr450g Tl-wvr450g Firmware Tl-wvr450l Tl-wvr450l Firmware Tl-wvr458 Tl-wvr458 Firmware Tl-wvr458l Tl-wvr458l Firmware Tl-wvr458p Tl-wvr458p Firmware Tl-wvr900g Tl-wvr900g Firmware Tl-wvr900l Tl-wvr900l Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T20:43:57.837Z

Reserved: 2017-11-27T00:00:00.000Z

Link: CVE-2017-16958

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-11-27T10:29:00.487

Modified: 2026-05-13T00:24:29.033

Link: CVE-2017-16958

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses