Vulnerabilities > TP Link > R4239G

DATE CVE VULNERABILITY TITLE RISK
2018-01-11 CVE-2017-15637 Unspecified vulnerability in Tp-Link products
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the pptphellointerval variable in the pptp_server.lua file.
network
low complexity
tp-link
critical
9.0
2018-01-11 CVE-2017-15636 Unspecified vulnerability in Tp-Link products
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-time variable in the webfilter.lua file.
network
low complexity
tp-link
critical
9.0
2018-01-11 CVE-2017-15635 Unspecified vulnerability in Tp-Link products
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the max_conn variable in the session_limits.lua file.
network
low complexity
tp-link
critical
9.0
2018-01-11 CVE-2017-15634 Unspecified vulnerability in Tp-Link products
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the name variable in the wportal.lua file.
network
low complexity
tp-link
critical
9.0
2018-01-11 CVE-2017-15633 Unspecified vulnerability in Tp-Link products
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-ipgroup variable in the session_limits.lua file.
network
low complexity
tp-link
critical
9.0
2018-01-11 CVE-2017-15632 Unspecified vulnerability in Tp-Link products
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-mppeencryption variable in the pptp_server.lua file.
network
low complexity
tp-link
critical
9.0
2018-01-11 CVE-2017-15631 Unspecified vulnerability in Tp-Link products
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-workmode variable in the pptp_client.lua file.
network
low complexity
tp-link
critical
9.0
2018-01-11 CVE-2017-15630 Unspecified vulnerability in Tp-Link products
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-remotesubnet variable in the pptp_client.lua file.
network
low complexity
tp-link
critical
9.0
2018-01-11 CVE-2017-15629 Unspecified vulnerability in Tp-Link products
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-tunnelname variable in the pptp_client.lua file.
network
low complexity
tp-link
critical
9.0
2018-01-11 CVE-2017-15628 Unspecified vulnerability in Tp-Link products
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the lcpechointerval variable in the pptp_server.lua file.
network
low complexity
tp-link
critical
9.0