9

CVE-2020-12109

Exploit

Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tp-linkNc200 Firmware Version2.1.6 Update160108_b
   Tp-linkNc200 Version-
Tp-linkNc200 Firmware Version2.1.9 Update200225
   Tp-linkNc200 Version-
Tp-linkNc210 Firmware Version1.0.3 Update160229
   Tp-linkNc210 Version-
Tp-linkNc210 Firmware Version1.0.4 Update160412
   Tp-linkNc210 Version-
Tp-linkNc210 Firmware Version1.0.9 Update200304
   Tp-linkNc210 Version-
Tp-linkNc220 Firmware Version1.2.0 Update170516
   Tp-linkNc220 Version-
Tp-linkNc220 Firmware Version1.3.0 Update180105
   Tp-linkNc220 Version-
Tp-linkNc220 Firmware Version1.3.0 Update200304
   Tp-linkNc220 Version-
Tp-linkNc230 Firmware Version1.0.3 Update160108
   Tp-linkNc230 Version-
Tp-linkNc230 Firmware Version1.2.1 Update170515
   Tp-linkNc230 Version-
Tp-linkNc230 Firmware Version1.3.0 Update200304
   Tp-linkNc230 Version-
Tp-linkNc250 Firmware Version1.0.8 Update160108
   Tp-linkNc250 Version-
Tp-linkNc250 Firmware Version1.0.10 Update160321
   Tp-linkNc250 Version-
Tp-linkNc250 Firmware Version1.2.1 Update170515
   Tp-linkNc250 Version-
Tp-linkNc250 Firmware Version1.3.0 Update200304
   Tp-linkNc250 Version-
Tp-linkNc260 Firmware Version1.0.5 Update160804
   Tp-linkNc260 Version-
Tp-linkNc260 Firmware Version1.0.6 Update161114
   Tp-linkNc260 Version-
Tp-linkNc260 Firmware Version1.4.1 Update180720
   Tp-linkNc260 Version-
Tp-linkNc260 Firmware Version1.5.0 Update181123
   Tp-linkNc260 Version-
Tp-linkNc260 Firmware Version1.5.2 Update200304
   Tp-linkNc260 Version-
Tp-linkNc450 Firmware Version1.0.15 Update160920
   Tp-linkNc450 Version-
Tp-linkNc450 Firmware Version1.1.2 Update161013
   Tp-linkNc450 Version-
Tp-linkNc450 Firmware Version1.3.4 Update171130
   Tp-linkNc450 Version-
Tp-linkNc450 Firmware Version1.5.3 Update200304
   Tp-linkNc450 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 83.46% 0.992
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.