CVE-2017-8220: TP-Link c20i Firmware

Critical severity, CVSS 9.9. EPSS: 37.2% chance of exploitation in the next 30 days.

TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow remote code execution with a single HTTP request by placing shell commands in a "host=" line within HTTP POST data.

Affected products

  • TP-Link c20i Firmware: up to and including 0.9.1_4.2_v0032.0_build_160706
  • TP-Link c2 Firmware: up to and including 0.9.1_4.2_v0032.0_build_160706

Published 2017-04-25. Last modified 2026-06-17.