First published: Fri Oct 11 2013(Updated: )
Unrestricted file upload vulnerability in cgi-bin/uploadfile in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6, allows remote attackers to upload arbitrary files, then accessing it via a direct request to the file in the mnt/mtd directory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TP-Link TL-SC3130G | ||
TP-Link TL-SC3130G Firmware | ||
TP-Link TL-SC3171G | ||
Tp-link TL-SC 3171G Firmware | ||
TP-Link LM Firmware | <=1.6.18p12_sign5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2580 has a high severity due to its potential for remote attackers to execute arbitrary file uploads.
To fix CVE-2013-2580, update the firmware of your TP-Link cameras to the beta firmware version LM.1.6.18P12_sign6 or later.
CVE-2013-2580 affects TP-Link IP cameras including the TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly others.
If CVE-2013-2580 is exploited, attackers can upload malicious files, potentially compromising the camera and network.
There are no official workarounds for CVE-2013-2580 apart from updating to the patched firmware.