9
CVE-2020-12109
- EPSS 83.46%
- Published 04.05.2020 16:15:12
- Last modified 21.11.2024 04:59:15
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.
Data is provided by the National Vulnerability Database (NVD)
Tp-link ≫ Nc200 Firmware Version2.1.6 Update160108_b
Tp-link ≫ Nc200 Firmware Version2.1.9 Update200225
Tp-link ≫ Nc210 Firmware Version1.0.3 Update160229
Tp-link ≫ Nc210 Firmware Version1.0.4 Update160412
Tp-link ≫ Nc210 Firmware Version1.0.9 Update200304
Tp-link ≫ Nc220 Firmware Version1.2.0 Update170516
Tp-link ≫ Nc220 Firmware Version1.3.0 Update180105
Tp-link ≫ Nc220 Firmware Version1.3.0 Update200304
Tp-link ≫ Nc230 Firmware Version1.0.3 Update160108
Tp-link ≫ Nc230 Firmware Version1.2.1 Update170515
Tp-link ≫ Nc230 Firmware Version1.3.0 Update200304
Tp-link ≫ Nc250 Firmware Version1.0.8 Update160108
Tp-link ≫ Nc250 Firmware Version1.0.10 Update160321
Tp-link ≫ Nc250 Firmware Version1.2.1 Update170515
Tp-link ≫ Nc250 Firmware Version1.3.0 Update200304
Tp-link ≫ Nc260 Firmware Version1.0.5 Update160804
Tp-link ≫ Nc260 Firmware Version1.0.6 Update161114
Tp-link ≫ Nc260 Firmware Version1.4.1 Update180720
Tp-link ≫ Nc260 Firmware Version1.5.0 Update181123
Tp-link ≫ Nc260 Firmware Version1.5.2 Update200304
Tp-link ≫ Nc450 Firmware Version1.0.15 Update160920
Tp-link ≫ Nc450 Firmware Version1.1.2 Update161013
Tp-link ≫ Nc450 Firmware Version1.3.4 Update171130
Tp-link ≫ Nc450 Firmware Version1.5.3 Update200304
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 83.46% | 0.992 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 9 | 8 | 10 |
AV:N/AC:L/Au:S/C:C/I:C/A:C
|
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.