CVE-2013-2578
high · 10cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the ServerName parameter and (2) other unspecified parameters.
10
CVSS
73.7%
EPSS (exploit prob.)
99th
EPSS percentile
2013-10-11
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-78
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| tp-link | tl-sc3130 | all versions |
| tp-link | tl-sc3130g | all versions |
| tp-link | tl-sc3171 | all versions |
| tp-link | tl-sc3171g | all versions |
| tp-link | lm_firmware | <= 1.6.18p12_sign5 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2013-2578