CVE-2020-12109: OS Command Injection
Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-12109?
CVE-2020-12109 is a vulnerability that allows Command Injection in certain TP-Link devices.
Which TP-Link devices are affected by CVE-2020-12109?
The TP-Link devices affected by CVE-2020-12109 are NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.
What is the severity of CVE-2020-12109?
CVE-2020-12109 has a severity rating of 8.8 (Critical).
How can I fix CVE-2020-12109?
To fix CVE-2020-12109, update the firmware of the affected TP-Link devices to the latest available version.
Where can I find more information about CVE-2020-12109?
You can find more information about CVE-2020-12109 on the following URLs: [1] http://packetstormsecurity.com/files/157531/TP-LINK-Cloud-Cameras-NCXXX-Bonjour-Command-Injection.html [2] http://packetstormsecurity.com/files/159222/TP-Link-Cloud-Cameras-NCXXX-Bonjour-Command-Injection.html [3] https://seclists.org/fulldisclosure/2020/May/2