Remote Code Execution Vulnerability in TP-Link C2 and C20i Devices
CVE-2017-8220
9.9CRITICAL
What is CVE-2017-8220?
TP-Link C2 and C20i devices are susceptible to a remote code execution vulnerability due to inadequate input validation. An attacker can exploit this flaw by crafting a specially crafted HTTP POST request containing shell commands in the 'host=' line. This allows unauthorized access and control over the device, leading to potential data breaches or malicious activities.