CVE-2020-12109
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.
Affected (24)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.1.6 160108_b |
| Running on/with | Platform Versions |
|---|---|
Tp Link Nc200 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.3 160229 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Nc210 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.2.0 170516 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Nc220 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.3 160108 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Nc230 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.10 160321 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Nc250 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.5 160804 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Nc260 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.15 160920 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Nc450 | All versions |
References (8)
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: cve@mitre.org
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Timeline
No history available yet.