PT-2017-18222 · Tp Link · Tp-Link C2+1

Pierre Kim

·

Publicado

2017-04-25

·

Atualizado

2017-05-09

·

CVE-2017-8219

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n
Description The issue allows for a denial-of-service (DoS) attack against the HTTP server by sending a crafted Cookie header to the "/cgi/ansi" API endpoint.
Recommendations For TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n, consider restricting access to the /cgi/ansi URI as a temporary workaround until a patch is available. Avoid using crafted Cookie headers in the affected API endpoint until the issue is resolved.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-8219

Produtos afetados

Tp-Link C2
Tp-Link C20I