CVE-2013-2573: OS Command Injection
A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wirelessmft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-SC 3130G, 3171G. and 4171G 1.6.18P12s, which could let a malicious user execute arbitrary code.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2573?
CVE-2013-2573 is considered a critical vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2013-2573?
To fix CVE-2013-2573, upgrade the firmware of your TP-Link IP camera to a version newer than 1.6.18P12.
Which devices are affected by CVE-2013-2573?
CVE-2013-2573 affects TP-Link IP Cameras TL-SC 3130, TL-SC 3130G, TL-SC 3171G, and TL-SC 4171G with firmware version 1.6.18P12 or earlier.
Can CVE-2013-2573 be exploited remotely?
Yes, CVE-2013-2573 can be exploited remotely, allowing attackers to execute commands on the device.
What mitigation can be taken for CVE-2013-2573 if I cannot update my firmware?
If unable to update firmware, consider restricting access to the device through firewalls or network segmentation.