Exploitation Summary
CVE-2013-2578 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 2 public exploits from researchers including Nicholas Starke <[email protected]>, including a Metasploit module exploits/linux/http/tp_link_sc2020n_authenticated_telnet_injection.
AI-analyzed exploit summary This advisory details multiple vulnerabilities in TP-Link TL-SC3171 IP cameras, including OS command injection, hard-coded credentials, and unauthenticated remote file uploads/firmware upgrades. It provides technical descriptions, proof-of-concept code, and attack paths.
Description
cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the ServerName parameter and (2) other unspecified parameters.
Exploits (2)
This advisory details multiple vulnerabilities in TP-Link TL-SC3171 IP cameras, including OS command injection, hard-coded credentials, and unauthenticated remote file uploads/firmware upgrades. It provides technical descriptions, proof-of-concept code, and attack paths.
This Metasploit module exploits an authenticated OS command injection vulnerability in TP-Link SC2020n Network Video Camera via the `/cgi-bin/admin/servetest` endpoint. It enables telnet access with root privileges by injecting a command to start a telnet daemon.