CVE-2013-2578

EXPLOITED

TP-Link IP Cameras <LM.1.6.18P12_sign6 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2013-2578 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 2 public exploits from researchers including Nicholas Starke <[email protected]>, including a Metasploit module exploits/linux/http/tp_link_sc2020n_authenticated_telnet_injection.

AI-analyzed exploit summary This advisory details multiple vulnerabilities in TP-Link TL-SC3171 IP cameras, including OS command injection, hard-coded credentials, and unauthenticated remote file uploads/firmware upgrades. It provides technical descriptions, proof-of-concept code, and attack paths.

Description

cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the ServerName parameter and (2) other unspecified parameters.

Exploits (2)

exploitdb WRITEUP
webappshardware
https://www.exploit-db.com/exploits/27289

This advisory details multiple vulnerabilities in TP-Link TL-SC3171 IP cameras, including OS command injection, hard-coded credentials, and unauthenticated remote file uploads/firmware upgrades. It provides technical descriptions, proof-of-concept code, and attack paths.

Classification
Writeup 100%
Attack Type
Rce | Auth Bypass | Info Leak
Complexity
Moderate
Reliability
Reliable
Target: TP-Link TL-SC3171 IP camera running firmware version LM.1.6.18P12_sign5
No auth needed
Prerequisites: Network access to the target device
devstral-2 · analyzed Feb 19, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Nicholas Starke <[email protected]> · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/tp_link_sc2020n_authenticated_telnet_injection.rb

This Metasploit module exploits an authenticated OS command injection vulnerability in TP-Link SC2020n Network Video Camera via the `/cgi-bin/admin/servetest` endpoint. It enables telnet access with root privileges by injecting a command to start a telnet daemon.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: TP-Link SC2020n Network Video Camera
Auth required
Prerequisites: Valid credentials for the TP-Link SC2020n web interface
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (1)

Core 1

Scores

EPSS 0.7454
EPSS Percentile 98.9%

Details

VulnCheck KEV 2020-07-04
CWE
CWE-78
Status published
Products (5)
tp-link/lm_firmware < 1.6.18p12_sign5
tp-link/tl-sc3130
tp-link/tl-sc3130g
tp-link/tl-sc3171
tp-link/tl-sc3171g
Published Oct 11, 2013
Tracked Since Feb 18, 2026