packetstormsecurity.com
http://packetstormsecurity.com/files/157531/TP-LINK-Cloud-Cameras-NCXXX-Bonjour-Command-Injection.html CVE-2020-12109
HIGH
TP-Link Cloud Cameras NCXXX Bonjour Command Injection
Record summary
CVE-2020-12109 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
MetasploitTP-Link Cloud Cameras NCXXX Bonjour Command InjectionMetasploit exploitby Pietro Oliva <pietroliva@gmail.com>Not analyzed1 file
References
5packetstormsecurity.com
http://packetstormsecurity.com/files/159222/TP-Link-Cloud-Cameras-NCXXX-Bonjour-Command-Injection.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-12109 seclists.org
https://seclists.org/fulldisclosure/2020/May/2 tp-link.com
https://www.tp-link.com/us/security