TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the max_conn variable in the session_limits.lua file.
Link | Tags |
---|---|
https://github.com/chunibalon/Vulnerability/blob/master/CVE-2017-15613_to_CVE-2017-15637.txt | third party advisory exploit |
http://www.securityfocus.com/archive/1/541655/100/0/threaded | mailing list third party advisory vdb entry exploit |