TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the max_conn variable in the session_limits.lua file.
https://github.com/chunibalon/Vulnerability/blob/master/CVE-2017-15613_to_CVE-2017-15637.txt
https://euvd.enisa.europa.eu/vulnerability/EUVD-2017-7086
http://www.securityfocus.com/archive/1/541655/100/0/threaded