Critical severity9.8NVD Advisory· Published Apr 25, 2017· Updated May 13, 2026
CVE-2017-8218
CVE-2017-8218
Description
vsftpd on TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n has a backdoor admin account with the 1234 password, a backdoor guest account with the guest password, and a backdoor test account with the test password.
Affected products
2- cpe:2.3:o:tp-link:c20i_firmware:*:rel.37961n:*:*:*:*:*:*Range: <=0.9.1_4.2_v0032.0_build_160706
- cpe:2.3:o:tp-link:c2_firmware:*:rel.37961n:*:*:*:*:*:*Range: <=0.9.1_4.2_v0032.0_build_160706
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- pierrekim.github.io/blog/2017-02-09-tplink-c2-and-c20i-vulnerable.htmlnvdExploitTechnical DescriptionThird Party Advisory
News mentions
0No linked articles in our index yet.