CVE-2020-12109
high · 8.8Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.
8.8
CVSS
74.3%
EPSS (exploit prob.)
99th
EPSS percentile
2020-05-04
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| tp-link | nc200_firmware | 2.1.6 |
| tp-link | nc200_firmware | 2.1.9 |
| tp-link | nc200 | all versions |
| tp-link | nc210_firmware | 1.0.3 |
| tp-link | nc210_firmware | 1.0.4 |
| tp-link | nc210_firmware | 1.0.9 |
| tp-link | nc210 | all versions |
| tp-link | nc220_firmware | 1.2.0 |
| tp-link | nc220_firmware | 1.3.0 |
| tp-link | nc220_firmware | 1.3.0 |
| tp-link | nc220 | all versions |
| tp-link | nc230_firmware | 1.0.3 |
| tp-link | nc230_firmware | 1.2.1 |
| tp-link | nc230_firmware | 1.3.0 |
| tp-link | nc230 | all versions |
| tp-link | nc250_firmware | 1.0.8 |
| tp-link | nc250_firmware | 1.0.10 |
| tp-link | nc250_firmware | 1.2.1 |
| tp-link | nc250_firmware | 1.3.0 |
| tp-link | nc250 | all versions |
| tp-link | nc260_firmware | 1.0.5 |
| tp-link | nc260_firmware | 1.0.6 |
| tp-link | nc260_firmware | 1.4.1 |
| tp-link | nc260_firmware | 1.5.0 |
| tp-link | nc260_firmware | 1.5.2 |
| tp-link | nc260 | all versions |
| tp-link | nc450_firmware | 1.0.15 |
| tp-link | nc450_firmware | 1.1.2 |
| tp-link | nc450_firmware | 1.3.4 |
| tp-link | nc450_firmware | 1.5.3 |
| tp-link | nc450 | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/157531/TP-LINK-Cloud-Cameras-NCXXX-Bonjour-Command-Injection.html
- http://packetstormsecurity.com/files/159222/TP-Link-Cloud-Cameras-NCXXX-Bonjour-Command-Injection.html
- https://seclists.org/fulldisclosure/2020/May/2
- https://www.tp-link.com/us/security
- http://packetstormsecurity.com/files/157531/TP-LINK-Cloud-Cameras-NCXXX-Bonjour-Command-Injection.html
- http://packetstormsecurity.com/files/159222/TP-Link-Cloud-Cameras-NCXXX-Bonjour-Command-Injection.html
- https://seclists.org/fulldisclosure/2020/May/2
- https://www.tp-link.com/us/security
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-12109