← Vulnerability feed

Vulnerability record · CVE-2017-16959 · published 27 November 2017

CVE-2017-16959: Tp-link tl-wvr300 firmware path traversal vulnerability

Tp Link · Tl Wvr300 Firmware

The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;locale=%0d request, and then making an operation=read request with a crafted Accept-Language HTTP header, related to the set_sysinfo and get_sysinfo functions in /usr/lib/lua/luci/controller/locale.lua in uhttpd.

6.5 CVSS 3.0 Medium EPSS 1.9% · top 21.0% CWE-22 · Path traversal
6.5CVSS 3.0 base score, v2 4.0
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
53Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;locale=%0d request, and then making an operation=read request with a crafted Accept-Language HTTP header, related to the set_sysinfo and get_sysinfo functions in /usr/lib/lua/luci/controller/locale.lua in uhttpd.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

53 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-16959 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-43135Tp-link tl-er5120g firmware missing authorization vulnerabilityThere is an unauthorized access vulnerability in TP-LINK ER5120G 4.0 2.0.0 Build 210817 Rel.80868n, which allows attackers to obtain sensitive inform…EPSS 0.92%8.8CVE-2023-43137Tp-link tl-er5120g firmware command injection vulnerabilityTPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds ACL rules after authentication, and …EPSS 2.4%8.8CVE-2023-43138Tp-link tl-er5120g firmware command injection vulnerabilityTPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds NAPT rules after authentication, and…EPSS 2.4%8.8CVE-2017-16957Tp-link tl-wvr300 firmware os command injection vulnerabilityTP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface …EPSS 5.6%8.8CVE-2017-16958Tp-link tl-wvr300 firmware os command injection vulnerabilityTP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bind…EPSS 2.9%8.8CVE-2017-16960Tp-link tl-er5510g os command injection vulnerabilityTP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bind…EPSS 2.4%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed

Source: NIST National Vulnerability Database (record CVE-2017-16959), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.