CVE-2017-16960 is a high-severity vulnerability affecting TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices, allowing remote authenticated users to execute arbitrary commands. This is due to improper sanitization of shell metacharacters in the t_bindif field of an admin/interface command. With a CVSS score of 8.8, an attacker can achieve full compromise (confidentiality, integrity, and availability) with low attack complexity and requiring only authenticated access. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and there is no evidence of active exploitation or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
v2CPE matchmatch criteria | cpe:2.3:h:tp-link:tl-er5510g:v2:*:*:*:*:*:*:* | ||
v3CPE matchmatch criteria | cpe:2.3:h:tp-link:tl-er5510g:v3:*:*:*:*:*:*:* | ||
v2CPE matchmatch criteria | cpe:2.3:h:tp-link:tl-er5520g:v2:*:*:*:*:*:*:* | ||
v3CPE matchmatch criteria | cpe:2.3:h:tp-link:tl-er5520g:v3:*:*:*:*:*:*:* | ||
v2CPE matchmatch criteria | cpe:2.3:h:tp-link:tl-er6120g:v2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.