Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-12109


Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.


Published

2020-05-04T16:15:12.087

Last Modified

2024-11-21T04:59:15.907

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System tp-link nc200_firmware 2.1.6 Yes
Operating System tp-link nc200_firmware 2.1.9 Yes
Hardware tp-link nc200 - No
Operating System tp-link nc210_firmware 1.0.3 Yes
Operating System tp-link nc210_firmware 1.0.4 Yes
Operating System tp-link nc210_firmware 1.0.9 Yes
Hardware tp-link nc210 - No
Operating System tp-link nc220_firmware 1.2.0 Yes
Operating System tp-link nc220_firmware 1.3.0 Yes
Operating System tp-link nc220_firmware 1.3.0 Yes
Hardware tp-link nc220 - No
Operating System tp-link nc230_firmware 1.0.3 Yes
Operating System tp-link nc230_firmware 1.2.1 Yes
Operating System tp-link nc230_firmware 1.3.0 Yes
Hardware tp-link nc230 - No
Operating System tp-link nc250_firmware 1.0.8 Yes
Operating System tp-link nc250_firmware 1.0.10 Yes
Operating System tp-link nc250_firmware 1.2.1 Yes
Operating System tp-link nc250_firmware 1.3.0 Yes
Hardware tp-link nc250 - No
Operating System tp-link nc260_firmware 1.0.5 Yes
Operating System tp-link nc260_firmware 1.0.6 Yes
Operating System tp-link nc260_firmware 1.4.1 Yes
Operating System tp-link nc260_firmware 1.5.0 Yes
Operating System tp-link nc260_firmware 1.5.2 Yes
Hardware tp-link nc260 - No
Operating System tp-link nc450_firmware 1.0.15 Yes
Operating System tp-link nc450_firmware 1.1.2 Yes
Operating System tp-link nc450_firmware 1.3.4 Yes
Operating System tp-link nc450_firmware 1.5.3 Yes
Hardware tp-link nc450 - No

References