CVE-2017-8217

MEDIUM

Tp-link C2 Firmware - Missing Authorization

Title source: rule

Description

TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n have too permissive iptables rules, e.g., SNMP is not blocked on any interface.

Scores

CVSS v3 5.3
EPSS 0.0025
EPSS Percentile 47.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Classification

CWE
CWE-862
Status published

Affected Products (3)

tp-link/c2_firmware < 0.9.1_4.2_v0032.0_build_160706
tp-link/c20i_firmware < 0.9.1_4.2_v0032.0_build_160706
n/a/n/a

Timeline

Published Apr 25, 2017
Tracked Since Feb 18, 2026