CVE-2017-8218: Critical severity TP-Link C2 Firmware vulnerability
vsftpd on TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n has a backdoor admin account with the 1234 password, a backdoor guest account with the guest password, and a backdoor test account with the test password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8218?
CVE-2017-8218 is considered a high severity vulnerability due to the existence of multiple backdoor accounts in the affected firmware.
How do I fix CVE-2017-8218?
To fix CVE-2017-8218, update your TP-Link C2 or C20i device firmware to a version that does not contain the backdoor accounts.
Which devices are affected by CVE-2017-8218?
CVE-2017-8218 affects TP-Link C2 and C20i devices running firmware version 0.9.1_4.2_v0032.0_build_160706.
Are there any default passwords associated with CVE-2017-8218?
Yes, CVE-2017-8218 involves default passwords for backdoor accounts: '1234' for admin, 'guest' for guest, and 'test' for test accounts.
What potential risks does CVE-2017-8218 pose?
CVE-2017-8218 poses serious security risks, allowing unauthorized access to the device and possible exploitation of the network.