PT-2016-3196 · Tp Link · C2+2

Pierre Kim

·

Publicado

2016-09-17

·

Atualizado

2019-10-03

·

CVE-2017-8218

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions vsftpd on TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n
Description The issue is related to the use of predefined accounts in the vsftpd component of the TP-Link C2 and C20i router firmware. The accounts include admin with password 1234, guest with password guest, and test with password test. Exploitation of this issue may allow a remote attacker to impact the confidentiality, integrity, and availability of data.
Recommendations For vsftpd on TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n, consider changing the default passwords of the admin, guest, and test accounts to prevent unauthorized access. As a temporary workaround, restrict access to these accounts until a patch is available.

Exploit

Correção

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02420
CVE-2017-8218

Produtos afetados

C2
C20I
Vsftpd