製品・ソフトウェアに関する情報
複数の TP-Link デバイスにおけるコマンドインジェクションの脆弱性
Title 複数の TP-Link デバイスにおけるコマンドインジェクションの脆弱性
Summary

複数の TP-Link デバイスには、コマンドインジェクションの脆弱性が存在します。

Possible impacts 情報を取得される、情報を改ざんされる、およびサービス運用妨害 (DoS) 状態にされる可能性があります。
Solution

ベンダ情報および参考情報を参照して適切な対策を実施してください。

Publication Date Nov. 28, 2017, midnight
Registration Date Dec. 26, 2017, 5:22 p.m.
Last Update Dec. 26, 2017, 5:22 p.m.
CVSS3.0 : 重要
Score 8.8
Vector CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS2.0 : 危険
Score 9
Vector AV:N/AC:L/Au:S/C:C/I:C/A:C
Affected System
TP-LINK Technologies
TL-ER3210G ファームウェア 
TL-ER3220G ファームウェア 
TL-ER5110G ファームウェア 
TL-ER5120G ファームウェア 
TL-ER5510G ファームウェア 
TL-ER5520G ファームウェア 
TL-ER6110G ファームウェア 
TL-ER6120G ファームウェア 
TL-ER6220G ファームウェア 
TL-ER6510G ファームウェア 
TL-ER6520G ファームウェア 
TL-ER7520G ファームウェア 
TL-R4149G ファームウェア 
TL-R4239G ファームウェア 
TL-R4299G ファームウェア 
TL-R473 ファームウェア 
TL-R473G ファームウェア 
TL-R473GP-AC ファームウェア 
TL-R473P-AC ファームウェア 
TL-R478 ファームウェア 
TL-R478+ ファームウェア 
TL-R478G ファームウェア 
TL-R478G+ ファームウェア 
TL-R479GP-AC ファームウェア 
TL-R479GPE-AC ファームウェア 
TL-R479P-AC ファームウェア 
TL-R483 ファームウェア 
TL-R483G ファームウェア 
TL-R488 ファームウェア 
TL-WAR1200L ファームウェア 
TL-WAR1300L ファームウェア 
TL-WAR1750L ファームウェア 
TL-WAR2600L ファームウェア 
TL-WAR302 ファームウェア 
TL-WAR450 ファームウェア 
TL-WAR450L ファームウェア 
TL-WAR458 ファームウェア 
TL-WAR458L ファームウェア 
TL-WAR900L ファームウェア 
TL-WVR1200L ファームウェア 
TL-WVR1300G ファームウェア 
TL-WVR1300L ファームウェア 
TL-WVR1750L ファームウェア 
TL-WVR2600L ファームウェア 
TL-WVR300 ファームウェア 
TL-WVR302 ファームウェア 
TL-WVR4300L ファームウェア 
TL-WVR450 ファームウェア 
TL-WVR450G ファームウェア 
TL-WVR450L ファームウェア 
TL-WVR458 ファームウェア 
TL-WVR458L ファームウェア 
TL-WVR458P ファームウェア 
TL-WVR900G ファームウェア 
TL-WVR900L ファームウェア 
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
その他
Change Log
No Changed Details Date of change
0 [2017年12月26日]
  掲載
Feb. 17, 2018, 10:37 a.m.

NVD Vulnerability Information
CVE-2017-16957
Summary

TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface field of an admin/diagnostic command to cgi-bin/luci, related to the zone_get_effect_devices function in /usr/lib/lua/luci/controller/admin/diagnostic.lua in uhttpd.

Publication Date Nov. 27, 2017, 7:29 p.m.
Registration Date Jan. 26, 2021, 1:18 p.m.
Last Update Nov. 21, 2024, 12:17 p.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:o:tp-link:tl-wvr300_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-wvr300:-:*:*:*:*:*:*:*
Configuration2 or higher or less more than less than
cpe:2.3:o:tp-link:tl-wvr302_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-wvr302:-:*:*:*:*:*:*:*
Configuration3 or higher or less more than less than
cpe:2.3:o:tp-link:tl-wvr450_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-wvr450:-:*:*:*:*:*:*:*
Configuration4 or higher or less more than less than
cpe:2.3:o:tp-link:tl-wvr450l_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-wvr450l:-:*:*:*:*:*:*:*
Configuration5 or higher or less more than less than
cpe:2.3:o:tp-link:tl-wvr450g_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-wvr450g:-:*:*:*:*:*:*:*
Configuration6 or higher or less more than less than
cpe:2.3:o:tp-link:tl-wvr458_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-wvr458:-:*:*:*:*:*:*:*
Configuration7 or higher or less more than less than
cpe:2.3:o:tp-link:tl-wvr458l_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-wvr458l:-:*:*:*:*:*:*:*
Configuration8 or higher or less more than less than
cpe:2.3:o:tp-link:tl-wvr458p_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-wvr458p:-:*:*:*:*:*:*:*
Configuration9 or higher or less more than less than
cpe:2.3:o:tp-link:tl-wvr900g_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-wvr900g:-:*:*:*:*:*:*:*
Configuration10 or higher or less more than less than
cpe:2.3:o:tp-link:tl-wvr900l_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-wvr900l:-:*:*:*:*:*:*:*
Configuration11 or higher or less more than less than
cpe:2.3:o:tp-link:tl-wvr1200l_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-wvr1200l:-:*:*:*:*:*:*:*
Configuration12 or higher or less more than less than
cpe:2.3:o:tp-link:tl-wvr1300l_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-wvr1300l:-:*:*:*:*:*:*:*
Configuration13 or higher or less more than less than
cpe:2.3:o:tp-link:tl-wvr1300g_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-war1300g:-:*:*:*:*:*:*:*
Configuration14 or higher or less more than less than
cpe:2.3:o:tp-link:tl-wvr1750l_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-wvr1750l:-:*:*:*:*:*:*:*
Configuration15 or higher or less more than less than
cpe:2.3:o:tp-link:tl-war2600l_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-wvr2600l:-:*:*:*:*:*:*:*
Configuration16 or higher or less more than less than
cpe:2.3:o:tp-link:tl-wvr4300l_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-wvr4300l:-:*:*:*:*:*:*:*
Configuration17 or higher or less more than less than
cpe:2.3:o:tp-link:tl-war302_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-war302:-:*:*:*:*:*:*:*
Configuration18 or higher or less more than less than
cpe:2.3:o:tp-link:tl-war450_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-war450:-:*:*:*:*:*:*:*
Configuration19 or higher or less more than less than
cpe:2.3:o:tp-link:tl-war450l_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-war450l:-:*:*:*:*:*:*:*
Configuration20 or higher or less more than less than
cpe:2.3:o:tp-link:tl-war458_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-war458:-:*:*:*:*:*:*:*
Configuration21 or higher or less more than less than
cpe:2.3:o:tp-link:tl-war458l_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-war458l:-:*:*:*:*:*:*:*
Configuration22 or higher or less more than less than
cpe:2.3:o:tp-link:tl-war900l_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-war900l:-:*:*:*:*:*:*:*
Configuration23 or higher or less more than less than
cpe:2.3:o:tp-link:tl-war1200l_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-war1200l:-:*:*:*:*:*:*:*
Configuration24 or higher or less more than less than
cpe:2.3:o:tp-link:tl-war1300l_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-war1300l:-:*:*:*:*:*:*:*
Configuration25 or higher or less more than less than
cpe:2.3:o:tp-link:tl-war1750l_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-war1750l:-:*:*:*:*:*:*:*
Configuration26 or higher or less more than less than
cpe:2.3:o:tp-link:tl-war2600l_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-war2600l:-:*:*:*:*:*:*:*
Configuration27 or higher or less more than less than
cpe:2.3:o:tp-link:tl-er3210g_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-er3210g:-:*:*:*:*:*:*:*
Configuration28 or higher or less more than less than
cpe:2.3:o:tp-link:tl-er3220g_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-er3220g:-:*:*:*:*:*:*:*
Configuration29 or higher or less more than less than
cpe:2.3:o:tp-link:tl-er5110g_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-er5110g:-:*:*:*:*:*:*:*
Configuration30 or higher or less more than less than
cpe:2.3:o:tp-link:tl-er5120g_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-er5120g:-:*:*:*:*:*:*:*
Configuration31 or higher or less more than less than
cpe:2.3:o:tp-link:tl-er5510g_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-er5510g:-:*:*:*:*:*:*:*
Configuration32 or higher or less more than less than
cpe:2.3:o:tp-link:tl-er5520g_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-er5520g:-:*:*:*:*:*:*:*
Configuration33 or higher or less more than less than
cpe:2.3:o:tp-link:tl-er6110g_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-er6110g:-:*:*:*:*:*:*:*
Configuration34 or higher or less more than less than
cpe:2.3:o:tp-link:tl-er6120g_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-er6120g:-:*:*:*:*:*:*:*
Configuration35 or higher or less more than less than
cpe:2.3:o:tp-link:tl-er6220g_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-er6220g:-:*:*:*:*:*:*:*
Configuration36 or higher or less more than less than
cpe:2.3:o:tp-link:tl-er6510g_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-er6510g:-:*:*:*:*:*:*:*
Configuration37 or higher or less more than less than
cpe:2.3:o:tp-link:tl-er6520g_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-er6520g:-:*:*:*:*:*:*:*
Configuration38 or higher or less more than less than
cpe:2.3:o:tp-link:tl-er7520g_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-er7520g:-:*:*:*:*:*:*:*
Configuration39 or higher or less more than less than
cpe:2.3:o:tp-link:tl-r473_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-r473:-:*:*:*:*:*:*:*
Configuration40 or higher or less more than less than
cpe:2.3:o:tp-link:tl-r473g_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-r473g:-:*:*:*:*:*:*:*
Configuration41 or higher or less more than less than
cpe:2.3:o:tp-link:tl-r473p-ac_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-r473p-ac:-:*:*:*:*:*:*:*
Configuration42 or higher or less more than less than
cpe:2.3:o:tp-link:tl-r479gp-ac_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-r473gp-ac:-:*:*:*:*:*:*:*
Configuration43 or higher or less more than less than
cpe:2.3:o:tp-link:tl-r478_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-r478:-:*:*:*:*:*:*:*
Configuration44 or higher or less more than less than
cpe:2.3:o:tp-link:tl-r478\+_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-r478\+:-:*:*:*:*:*:*:*
Configuration45 or higher or less more than less than
cpe:2.3:o:tp-link:tl-r478g_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-r478g:-:*:*:*:*:*:*:*
Configuration46 or higher or less more than less than
cpe:2.3:o:tp-link:tl-r478g\+_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-r478g\+:-:*:*:*:*:*:*:*
Configuration47 or higher or less more than less than
cpe:2.3:o:tp-link:tl-r479p-ac_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-r479p-ac:-:*:*:*:*:*:*:*
Configuration48 or higher or less more than less than
cpe:2.3:o:tp-link:tl-r479gp-ac_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-r479gp-ac:-:*:*:*:*:*:*:*
Configuration49 or higher or less more than less than
cpe:2.3:o:tp-link:tl-r479gpe-ac_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-r479gpe-ac:-:*:*:*:*:*:*:*
Configuration50 or higher or less more than less than
cpe:2.3:o:tp-link:tl-r483_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-r483:-:*:*:*:*:*:*:*
Configuration51 or higher or less more than less than
cpe:2.3:o:tp-link:tl-r483g_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-r483g:-:*:*:*:*:*:*:*
Configuration52 or higher or less more than less than
cpe:2.3:o:tp-link:tl-r488_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-r488:-:*:*:*:*:*:*:*
Configuration53 or higher or less more than less than
cpe:2.3:o:tp-link:tl-r4149g_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-r4149g:-:*:*:*:*:*:*:*
Configuration54 or higher or less more than less than
cpe:2.3:o:tp-link:tl-r4239g_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-r4239g:-:*:*:*:*:*:*:*
Configuration55 or higher or less more than less than
cpe:2.3:o:tp-link:tl-r4299g_firmware:-:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:tp-link:tl-r4299g:-:*:*:*:*:*:*:*
Related information, measures and tools
Common Vulnerabilities List