← All CVEs

CVE-2013-2578

high · 10

cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the ServerName parameter and (2) other unspecified parameters.

10
CVSS
73.7%
EPSS (exploit prob.)
99th
EPSS percentile
2013-10-11
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
tp-linktl-sc3130all versions
tp-linktl-sc3130gall versions
tp-linktl-sc3171all versions
tp-linktl-sc3171gall versions
tp-linklm_firmware<= 1.6.18p12_sign5

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-2578