First published: Mon May 04 2020(Updated: )
Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TP-Link NC200 Firmware | =2.1.6-160108_b | |
TP-Link NC200 Firmware | =2.1.9-200225 | |
TP-LINK NC200 | ||
TP-Link NC210 | =1.0.3-160229 | |
TP-Link NC210 | =1.0.4-160412 | |
TP-Link NC210 | =1.0.9-200304 | |
TP-Link NC210 Firmware | ||
TP-Link NC220 | =1.2.0-170516 | |
TP-Link NC220 | =1.3.0-180105 | |
TP-Link NC220 | =1.3.0-200304 | |
TP-Link NC220 Firmware | ||
TP-Link NC230 | =1.0.3-160108 | |
TP-Link NC230 | =1.2.1-170515 | |
TP-Link NC230 | =1.3.0-200304 | |
TP-Link NC230 | ||
TP-Link NC250 Firmware | =1.0.8-160108 | |
TP-Link NC250 Firmware | =1.0.10-160321 | |
TP-Link NC250 Firmware | =1.2.1-170515 | |
TP-Link NC250 Firmware | =1.3.0-200304 | |
TP-Link NC250 Firmware | ||
TP-Link NC260 Firmware | =1.0.5-160804 | |
TP-Link NC260 Firmware | =1.0.6-161114 | |
TP-Link NC260 Firmware | =1.4.1-180720 | |
TP-Link NC260 Firmware | =1.5.0-181123 | |
TP-Link NC260 Firmware | =1.5.2-200304 | |
TP-Link NC260 Firmware | ||
TP-Link NC450 Firmware | =1.0.15-160920 | |
TP-Link NC450 Firmware | =1.1.2-161013 | |
TP-Link NC450 Firmware | =1.3.4-171130 | |
TP-Link NC450 Firmware | =1.5.3-200304 | |
TP-Link NC450 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The TP-Link devices affected by CVE-2020-12110 include NC200, NC210, NC220, NC230, NC250, NC260, and NC450.
The vulnerability severity of CVE-2020-12110 is critical with a severity value of 9.8.
The CWE ID associated with CVE-2020-12110 is CWE-798.
There is currently no known fix for the vulnerability in TP-Link devices affected by CVE-2020-12110. It is recommended to contact the vendor for further information and updates.
You can find more information about CVE-2020-12110 at the following references: [Link 1](http://packetstormsecurity.com/files/157532/TP-LINK-Cloud-Cameras-NCXXX-Hardcoded-Encryption-Key.html), [Link 2](https://seclists.org/fulldisclosure/2020/May/3).