CVE-2017-16959

Published: Nov 27, 2017 Last Modified: Apr 20, 2025 EU-VD ID: EUVD-2017-8128 Aliases: GSD-2017-16959
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,5
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: none
Availability: none
MEDIUM 4,0
Access Vector: network
Access Complexity: low
Authentication: single
Confidentiality: partial
Integrity: none
Availability: none

Description

AI Translation Available

The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;locale=%0d request, and then making an operation=read request with a crafted Accept-Language HTTP header, related to the set_sysinfo and get_sysinfo functions in /usr/lib/lua/luci/controller/locale.lua in uhttpd.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0038
Percentile
0,6th
Updated

EPSS Score Trend (Last 90 Days)

22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Stable
Common Consequences
Security Scopes Affected:
Integrity Confidentiality Availability
Potential Impacts:
Execute Unauthorized Code Or Commands Modify Files Or Directories Read Files Or Directories Dos: Crash, Exit, Or Restart
Applicable Platforms
Technologies: AI/ML
View CWE Details
Operating System

Tl-R4239G Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-r4239g_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-R479Gpe-Ac Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-r479gpe-ac_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-War1200L Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-war1200l_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Er6520G Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-er6520g_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Er5510G Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-er5510g_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Wvr450 Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-wvr450_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-R4149G Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-r4149g_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Wvr4300L Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-wvr4300l_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-R479P-Ac Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-r479p-ac_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-War302 Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-war302_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-R483G Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-r483g_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-R483 Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-r483_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Er5520G Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-er5520g_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-R473P-Ac Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-r473p-ac_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Er3220G Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-er3220g_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-R478G Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-r478g_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Wvr1200L Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-wvr1200l_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Er5120G Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-er5120g_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Er6110G Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-er6110g_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Er6120G Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-er6120g_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-R488 Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-r488_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-War900L Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-war900l_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Er6220G Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-er6220g_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-R473G Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-r473g_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Wvr900G Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-wvr900g_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-R478G\+ Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-r478g\+_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-War1750L Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-war1750l_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-R479Gp-Ac Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-r479gp-ac_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-R4299G Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-r4299g_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-R478 Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-r478_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Wvr458 Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-wvr458_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Er5110G Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-er5110g_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Wvr302 Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-wvr302_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Wvr1300G Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-wvr1300g_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Wvr300 Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-wvr300_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-R478\+ Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-r478\+_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Wvr1750L Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-wvr1750l_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-War458 Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-war458_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-War450 Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-war450_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Wvr458L Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-wvr458l_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Er7520G Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-er7520g_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-War2600L Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-war2600l_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Wvr450L Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-wvr450l_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-War458L Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-war458l_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Wvr450G Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-wvr450g_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Wvr1300L Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-wvr1300l_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-R473 Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-r473_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Wvr900L Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-wvr900l_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Wvr458P Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-wvr458p_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-War1300L Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-war1300l_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Er3210G Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-er3210g_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-Er6510G Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-er6510g_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tl-War450L Firmware by Tp-Link

cpe:2.3:o:tp-link:tl-war450l_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://github.com/coincoin7/Wireless-Router-Vulnerability/blob/master/TplinkLo…
https://github.com/coincoin7/Wireless-Router-Vulnerability/blob/master/TplinkLo…