CVE-2013-2579

TP-Link IP Cameras <LM.1.6.18P12_sign6 - Auth Bypass

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-2579.

AI-analyzed exploit summary This advisory details multiple vulnerabilities in TP-Link TL-SC3171 IP cameras, including OS command injection, hard-coded credentials, and unauthenticated remote file uploads/firmware upgrades. It provides technical descriptions, proof-of-concept code snippets, and attack paths.

Description

TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 have an empty password for the hardcoded "qmik" account, which allows remote attackers to obtain administrative access via a TELNET session.

Exploits (1)

exploitdb WRITEUP
webappshardware
https://www.exploit-db.com/exploits/27289

This advisory details multiple vulnerabilities in TP-Link TL-SC3171 IP cameras, including OS command injection, hard-coded credentials, and unauthenticated remote file uploads/firmware upgrades. It provides technical descriptions, proof-of-concept code snippets, and attack paths.

Classification
Writeup 100%
Attack Type
Rce | Auth Bypass | Info Leak
Complexity
Moderate
Reliability
Reliable
Target: TP-Link TL-SC3171 IP camera running firmware version LM.1.6.18P12_sign5
No auth needed
Prerequisites: Network access to the vulnerable device
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (1)

Core 1

Scores

EPSS 0.0390
EPSS Percentile 88.9%

Details

CWE
CWE-255
Status published
Products (5)
tp-link/lm_firmware < 1.6.18p12_sign5
tp-link/tl-sc3130
tp-link/tl-sc3130g
tp-link/tl-sc3171
tp-link/tl-sc3171g
Published Oct 11, 2013
Tracked Since Feb 18, 2026