CVE-2013-2578: OS Command Injection
Published Oct 11, 2013
·Updated
cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12sign6 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the ServerName parameter and (2) other unspecified parameters.
Affected Software
5 affected components
TP-Link TL-SC3130
TP-Link TL-SC3130G
TP-Link TL-SC3171
TP-Link TL-SC3171G
TP-Link Lm Firmware<=1.6.18p12_sign5
Event History
Oct 11, 2013
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-2578?
CVE-2013-2578 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2013-2578?
To fix CVE-2013-2578, upgrade the firmware of your TP-Link camera to the latest version.
3
Which TP-Link camera models are affected by CVE-2013-2578?
CVE-2013-2578 affects TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly others.
4
Can CVE-2013-2578 be exploited remotely?
Yes, CVE-2013-2578 can be exploited remotely by attackers through crafted requests.
5
What type of vulnerability is CVE-2013-2578 classified as?
CVE-2013-2578 is classified as a command injection vulnerability.