First published: Wed Jan 29 2020(Updated: )
A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-SC 3130G, 3171G. and 4171G 1.6.18P12s, which could let a malicious user execute arbitrary code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TP-Link TL-SC3130G Firmware | <=1.6.18p12 | |
TP-Link TL-SC3130G | ||
TP-Link TL-SC 3171G Firmware | <=1.6.18p12 | |
TP-Link TL-SC3171G | ||
TP-Link TL-SC4171G Firmware | <=1.6.18p12 | |
TP-Link TL-SC4171G Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2573 is considered a critical vulnerability due to the potential for arbitrary code execution.
To fix CVE-2013-2573, upgrade the firmware of your TP-Link IP camera to a version newer than 1.6.18P12.
CVE-2013-2573 affects TP-Link IP Cameras TL-SC 3130, TL-SC 3130G, TL-SC 3171G, and TL-SC 4171G with firmware version 1.6.18P12 or earlier.
Yes, CVE-2013-2573 can be exploited remotely, allowing attackers to execute commands on the device.
If unable to update firmware, consider restricting access to the device through firewalls or network segmentation.