
Cloud Vulnerability DB
A community-led vulnerabilities database
TP-Link WVR, WAR and ER devices contain a command injection vulnerability (CVE-2018-15632) that allows remote authenticated administrators to execute arbitrary commands via the new-mppeencryption variable in the pptp_server.lua file. The vulnerability was discovered in 2018 and affects multiple TP-Link router models (NVD).
The vulnerability has a CVSS v3.0 base score of 7.2 (High) with vector string CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H. It requires network access and high privileges but no user interaction. The vulnerability allows for complete compromise of system confidentiality, integrity and availability through command injection in the pptp_server.lua file (NVD).
Successful exploitation of this vulnerability allows an authenticated administrator to execute arbitrary commands on the affected device with elevated privileges. This could lead to complete system compromise including unauthorized access to sensitive data, modification of system configurations, and disruption of services (NVD).
The vulnerability requires network access and high privileges (administrator access) to exploit. Proof-of-concept exploit code is publicly available (SecurityFocus, GitHub).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."