PT-2016-3196 · Tp Link · C2+2
Pierre Kim
·
Publicado
2016-09-17
·
Atualizado
2019-10-03
·
CVE-2017-8218
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
vsftpd on TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n
Description
The issue is related to the use of predefined accounts in the vsftpd component of the TP-Link C2 and C20i router firmware. The accounts include
admin with password 1234, guest with password guest, and test with password test. Exploitation of this issue may allow a remote attacker to impact the confidentiality, integrity, and availability of data.Recommendations
For vsftpd on TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n, consider changing the default passwords of the
admin, guest, and test accounts to prevent unauthorized access. As a temporary workaround, restrict access to these accounts until a patch is available.Exploit
Correção
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
C2
C20I
Vsftpd