VYPR

C20i Firmware

Sign in to watch

by TP-Link

CVEs (3)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-8218Cri0.649.80.01Apr 25, 2017vsftpd on TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n has a backdoor admin account with the 1234 password, a backdoor guest account with the guest password, and a backdoor test account with the test password.
CVE-2017-8219Med0.426.50.00Apr 25, 2017TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow DoSing the HTTP server via a crafted Cookie header to the /cgi/ansi URI.
CVE-2017-8217Med0.345.30.00Apr 25, 2017TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n have too permissive iptables rules, e.g., SNMP is not blocked on any interface.