Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
Low
Attack Vector
Network
0

CVE-2020-12109

Disclosure Date: May 04, 2020
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
8.8 High
Impact Score:
5.9
Exploitability Score:
2.8
Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
Low
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
High
Availability (A):
High

General Information

Vendors

  • tp-link

Products

  • nc200 firmware 2.1.6,
  • nc200 firmware 2.1.9,
  • nc210 firmware 1.0.3,
  • nc210 firmware 1.0.4,
  • nc210 firmware 1.0.9,
  • nc220 firmware 1.2.0,
  • nc220 firmware 1.3.0,
  • nc230 firmware 1.0.3,
  • nc230 firmware 1.2.1,
  • nc230 firmware 1.3.0,
  • nc250 firmware 1.0.10,
  • nc250 firmware 1.0.8,
  • nc250 firmware 1.2.1,
  • nc250 firmware 1.3.0,
  • nc260 firmware 1.0.5,
  • nc260 firmware 1.0.6,
  • nc260 firmware 1.4.1,
  • nc260 firmware 1.5.0,
  • nc260 firmware 1.5.2,
  • nc450 firmware 1.0.15,
  • nc450 firmware 1.1.2,
  • nc450 firmware 1.3.4,
  • nc450 firmware 1.5.3
Technical Analysis