Vulnerability Details CVE-2017-8220
TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow remote code execution with a single HTTP request by placing shell commands in a "host=" line within HTTP POST data.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.119
EPSS Ranking 93.4%
CVSS Severity
CVSS v3 Score 9.9
CVSS v2 Score 9.0
Products affected by CVE-2017-8220
-
-
-
cpe:2.3:o:tp-link:c20i_firmware:0.9.1_4.2_v0032.0_build_160706
-
cpe:2.3:o:tp-link:c2_firmware:0.9.1_4.2_v0032.0_build_160706