9
CVSSv2

CVE-2017-8220

Published: 25/04/2017 Updated: 03/10/2019
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 9.9 | Impact Score: 6 | Exploitability Score: 3.1
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow remote code execution with a single HTTP request by placing shell commands in a "host=" line within HTTP POST data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tp-link c2_firmware

tp-link c20i_firmware

Github Repositories

Collection of exploits created by NSIDE ATTACK LOGIC GmbH

Exploit-Collection Collection of exploits created by NSIDE ATTACK LOGIC GmbH O2_HomeBox_6441_v010130py NSIDE discovered a buffer overflow in the webserver of the HomeBox 6441 in firmware 010130 The vulnerability was reported and resolved in 2018 Blogpost Article by Heisede TP-Link-WR841ND_v091_416py While NSIDE analyzed CVE-2017-8220 for an IoT hacking series articl