CVE-2017-8220: OS Command Injection
TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow remote code execution with a single HTTP request by placing shell commands in a "host=" line within HTTP POST data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8220?
CVE-2017-8220 is considered a high-severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2017-8220?
To fix CVE-2017-8220, users should update their TP-Link C2 and C20i devices to the latest firmware version available.
What devices are affected by CVE-2017-8220?
CVE-2017-8220 affects TP-Link C2 and C20i devices running firmware versions up to 0.9.1 4.2 v0032.0 Build 160706.
What is the impact of exploiting CVE-2017-8220?
Exploiting CVE-2017-8220 allows an attacker to execute arbitrary shell commands remotely on the affected TP-Link devices.
How can CVE-2017-8220 be exploited?
CVE-2017-8220 can be exploited by sending a specially crafted HTTP POST request containing shell commands in the "host=" line.