EIP-2026-101479

PRE-CVE

TP-Link NC200/NC220 Cloud Camera 300Mbps Wi-Fi - Hard-Coded Credentials

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101479. PoCs published by LiquidWorm.

AI-analyzed exploit summary The writeup details hard-coded credentials (root:root) in TP-Link NC200/NC220 Cloud Camera firmware, extracted via strings and cracked using John the Ripper. It provides technical steps and output demonstrating the vulnerability.

Description

TP-Link NC200/NC220 Cloud Camera 300Mbps Wi-Fi - Hard-Coded Credentials

Exploits (1)

exploitdb WRITEUP
by LiquidWorm · textremotehardware
https://www.exploit-db.com/exploits/38186

The writeup details hard-coded credentials (root:root) in TP-Link NC200/NC220 Cloud Camera firmware, extracted via strings and cracked using John the Ripper. It provides technical steps and output demonstrating the vulnerability.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: TP-Link NC200 V1 2.0.15 Build 150701 Rel.20962, NC220 V1 1.0.28 Build 150629 Rel.22346
No auth needed
Prerequisites: Access to the firmware binary
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026