6.5

CVE-2017-8219

Exploit
TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow DoSing the HTTP server via a crafted Cookie header to the /cgi/ansi URI.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tp-link ≫ C2 Firmware Update rel.37961n Version <= 0.9.1_4.2_v0032.0_build_160706
   Tp-link ≫ C2 Version -
Tp-link ≫ C20i Firmware Update rel.37961n Version <= 0.9.1_4.2_v0032.0_build_160706
   Tp-link ≫ C20i Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.15% 0.631
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://pierrekim.github.io/blog/2017-02-09-tplink-c2-and-c20i-vulnerable.html
Third Party Advisory
Exploit
Technical Description