Summary
Detail | |||
---|---|---|---|
Vendor | Tp-Link | First view | 2017-11-27 |
Product | Tl-wvr450g Firmware | Last view | 2017-11-27 |
Version | Type | Os | |
Update | |||
Edition | |||
Language | |||
Sofware Edition | |||
Target Software | |||
Target Hardware | |||
Other |
Activity : Overall
COMMON PLATFORM ENUMERATION: Repartition per Version
CPE Name | Affected CVE |
---|---|
cpe:2.3:o:tp-link:tl-wvr450g_firmware:-:*:*:*:*:*:*:* | 3 |
Related : CVE
Date | Alert | Description | |
---|---|---|---|
6.5 | 2017-11-27 | CVE-2017-16959 | The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;locale=%0d request, and then making an operation=read request with a crafted Accept-Language HTTP header, related to the set_sysinfo and get_sysinfo functions in /usr/lib/lua/luci/controller/locale.lua in uhttpd. |
8.8 | 2017-11-27 | CVE-2017-16958 | TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/bridge command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/bridge.lua in uhttpd. |
8.8 | 2017-11-27 | CVE-2017-16957 | TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface field of an admin/diagnostic command to cgi-bin/luci, related to the zone_get_effect_devices function in /usr/lib/lua/luci/controller/admin/diagnostic.lua in uhttpd. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
66% (2) | CWE-78 | Improper Sanitization of Special Elements used in an OS Command ('O... |
33% (1) | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path ... |