| Summary | TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/interface.lua in uhttpd. |
|---|---|
| Publication Date | Nov. 27, 2017, 7:29 p.m. |
| Registration Date | Jan. 26, 2021, 1:18 p.m. |
| Last Update | Nov. 21, 2024, 12:17 p.m. |
| CVSS3.0 : HIGH | |
| スコア | 8.8 |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 攻撃元区分(AV) | ネットワーク |
| 攻撃条件の複雑さ(AC) | 低 |
| 攻撃に必要な特権レベル(PR) | 低 |
| 利用者の関与(UI) | 不要 |
| 影響の想定範囲(S) | 変更なし |
| 機密性への影響(C) | 高 |
| 完全性への影響(I) | 高 |
| 可用性への影響(A) | 高 |
| CVSS2.0 : HIGH | |
| Score | 9.0 |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
| 攻撃元区分(AV) | ネットワーク |
| 攻撃条件の複雑さ(AC) | 低 |
| 攻撃前の認証要否(Au) | 単一 |
| 機密性への影響(C) | 高 |
| 完全性への影響(I) | 高 |
| 可用性への影響(A) | 高 |
| Get all privileges. | いいえ |
| Get user privileges | いいえ |
| Get other privileges | いいえ |
| User operation required | いいえ |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:h:tp-link:tl-wvr300:v4:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:tp-link:tl-wvr302:v2:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:tp-link:tl-wvr450g:v5:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:tp-link:tl-wvr900g:v3:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:tp-link:tl-er5510g:v2:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:tp-link:tl-er5510g:v3:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:tp-link:tl-er5520g:v2:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:tp-link:tl-er5520g:v3:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:tp-link:tl-er6120g:v2:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:tp-link:tl-er6520g:v2:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:tp-link:tl-er6520g:v3:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:tp-link:tl-r473:v5:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:tp-link:tl-r478:v6:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:tp-link:tl-r478\+:v7:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:tp-link:tl-r478g\+:v3:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:tp-link:tl-r483:v5:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:tp-link:tl-r483g:v2:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:tp-link:tl-r488:v5:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:tp-link:tl-r4239g:v2:*:*:*:*:*:*:* | |||||
| cpe:2.3:h:tp-link:tl-r4299g:v2:*:*:*:*:*:*:* | |||||
| Configuration2 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-wvr450_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-wvr450:-:*:*:*:*:*:*:* | ||||
| Configuration3 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-wvr450l_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-wvr450l:-:*:*:*:*:*:*:* | ||||
| Configuration4 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-wvr458_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-wvr458:-:*:*:*:*:*:*:* | ||||
| Configuration5 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-wvr458l_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-wvr458l:-:*:*:*:*:*:*:* | ||||
| Configuration6 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-wvr458p_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-wvr458p:*:*:*:*:*:*:*:* | ||||
| Configuration7 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-wvr900l_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-wvr900l:-:*:*:*:*:*:*:* | ||||
| Configuration8 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-wvr1200l_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-wvr1200l:-:*:*:*:*:*:*:* | ||||
| Configuration9 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-wvr1300l_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-wvr1300l:-:*:*:*:*:*:*:* | ||||
| Configuration10 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-wvr1300g_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-wvr1300g:-:*:*:*:*:*:*:* | ||||
| Configuration11 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-wvr1750l_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-wvr1750l:-:*:*:*:*:*:*:* | ||||
| Configuration12 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-wvr2600l_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-wvr2600l:-:*:*:*:*:*:*:* | ||||
| Configuration13 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-wvr4300l_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-wvr4300l:-:*:*:*:*:*:*:* | ||||
| Configuration14 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-war302_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-war302:-:*:*:*:*:*:*:* | ||||
| Configuration15 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-war450_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-war450:-:*:*:*:*:*:*:* | ||||
| Configuration16 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-war450l_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-war450l:-:*:*:*:*:*:*:* | ||||
| Configuration17 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-war458_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-war458:-:*:*:*:*:*:*:* | ||||
| Configuration18 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-war458l_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-war458l:-:*:*:*:*:*:*:* | ||||
| Configuration19 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-war900l_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-war900l:-:*:*:*:*:*:*:* | ||||
| Configuration20 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-war1200l_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-war1200l:-:*:*:*:*:*:*:* | ||||
| Configuration21 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-war1300l_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-war1300l:-:*:*:*:*:*:*:* | ||||
| Configuration22 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-war1750l_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-war1750l:-:*:*:*:*:*:*:* | ||||
| Configuration23 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-war2600l_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-war2600l:-:*:*:*:*:*:*:* | ||||
| Configuration24 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-er3210g_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-er3210g:-:*:*:*:*:*:*:* | ||||
| Configuration25 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-er3220g_firmware:*:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-er3220g:-:*:*:*:*:*:*:* | ||||
| Configuration26 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-er5110g_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-er5110g:-:*:*:*:*:*:*:* | ||||
| Configuration27 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-er5120g_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-er5120g:-:*:*:*:*:*:*:* | ||||
| Configuration28 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-er6110g_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-er6110g:-:*:*:*:*:*:*:* | ||||
| Configuration29 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-er6220g_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-er6220g:-:*:*:*:*:*:*:* | ||||
| Configuration30 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-er6510g_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-er6510g:-:*:*:*:*:*:*:* | ||||
| Configuration31 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-er7520g_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-er7520g:-:*:*:*:*:*:*:* | ||||
| Configuration32 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-r473g_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-r473g:-:*:*:*:*:*:*:* | ||||
| Configuration33 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-r473p-ac_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-r473p-ac:-:*:*:*:*:*:*:* | ||||
| Configuration34 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-r473gp-ac_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-r473gp-ac:-:*:*:*:*:*:*:* | ||||
| Configuration35 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-r478g_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-r478g:-:*:*:*:*:*:*:* | ||||
| Configuration36 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-r478g_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-r478g:-:*:*:*:*:*:*:* | ||||
| Configuration37 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-r479p-ac_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-r479p-ac:-:*:*:*:*:*:*:* | ||||
| Configuration38 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-r479gp-ac_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-r479gp-ac:-:*:*:*:*:*:*:* | ||||
| Configuration39 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-r479gpe-ac_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-r479gpe-ac:-:*:*:*:*:*:*:* | ||||
| Configuration40 | or higher | or less | more than | less than | |
| cpe:2.3:o:tp-link:tl-r4149g_firmware:-:*:*:*:*:*:*:* | |||||
| execution environment | |||||
| 1 | cpe:2.3:h:tp-link:tl-r4149g:-:*:*:*:*:*:*:* | ||||
| Title | 複数の TP-Link デバイスにおけるコマンドインジェクションの脆弱性 |
|---|---|
| Summary | 複数の TP-Link デバイスには、コマンドインジェクションの脆弱性が存在します。 |
| Possible impacts | 情報を取得される、情報を改ざんされる、およびサービス運用妨害 (DoS) 状態にされる可能性があります。 |
| Solution | ベンダ情報および参考情報を参照して適切な対策を実施してください。 |
| Publication Date | Nov. 27, 2017, midnight |
| Registration Date | Dec. 22, 2017, 4:44 p.m. |
| Last Update | Dec. 22, 2017, 4:44 p.m. |
| TP-LINK Technologies |
| TL-ER3210G ファームウェア |
| TL-ER3220G ファームウェア |
| TL-ER5110G ファームウェア |
| TL-ER5120G ファームウェア |
| TL-ER5510G ファームウェア |
| TL-ER5520G ファームウェア |
| TL-ER6110G ファームウェア |
| TL-ER6120G ファームウェア |
| TL-ER6220G ファームウェア |
| TL-ER6510G ファームウェア |
| TL-ER6520G ファームウェア |
| TL-ER7520G ファームウェア |
| TL-R4149G ファームウェア |
| TL-R4239G ファームウェア |
| TL-R4299G ファームウェア |
| TL-R473 ファームウェア |
| TL-R473G ファームウェア |
| TL-R473GP-AC ファームウェア |
| TL-R473P-AC ファームウェア |
| TL-R478 ファームウェア |
| TL-R478+ ファームウェア |
| TL-R478G ファームウェア |
| TL-R478G+ ファームウェア |
| TL-R479GP-AC ファームウェア |
| TL-R479GPE-AC ファームウェア |
| TL-R479P-AC ファームウェア |
| TL-R483 ファームウェア |
| TL-R483G ファームウェア |
| TL-R488 ファームウェア |
| TL-WAR1200L ファームウェア |
| TL-WAR1300L ファームウェア |
| TL-WAR1750L ファームウェア |
| TL-WAR2600L ファームウェア |
| TL-WAR302 ファームウェア |
| TL-WAR450 ファームウェア |
| TL-WAR450L ファームウェア |
| TL-WAR458 ファームウェア |
| TL-WAR458L ファームウェア |
| TL-WAR900L ファームウェア |
| TL-WVR1200L ファームウェア |
| TL-WVR1300G ファームウェア |
| TL-WVR1300L ファームウェア |
| TL-WVR1750L ファームウェア |
| TL-WVR2600L ファームウェア |
| TL-WVR300 ファームウェア |
| TL-WVR302 ファームウェア |
| TL-WVR4300L ファームウェア |
| TL-WVR450 ファームウェア |
| TL-WVR450G ファームウェア |
| TL-WVR450L ファームウェア |
| TL-WVR458 ファームウェア |
| TL-WVR458L ファームウェア |
| TL-WVR458P ファームウェア |
| TL-WVR900G ファームウェア |
| TL-WVR900L ファームウェア |
| No | Changed Details | Date of change |
|---|---|---|
| 0 | [2017年12月22日] 掲載 |
Feb. 17, 2018, 10:37 a.m. |