10
CVSSv2

CVE-2013-2578

Published: 11/10/2013 Updated: 15/10/2013
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote malicious users to execute arbitrary commands via shell metacharacters in (1) the ServerName parameter and (2) other unspecified parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

tp-link tl-sc3171 -

tp-link tl-sc3171g -

tp-link tl-sc3130 -

tp-link tl-sc3130g -

tp-link lm_firmware

Exploits

Core Security - Corelabs Advisory corelabscoresecuritycom/ Multiple Vulnerabilities in TP-Link TL-SC3171 IP Cameras 1 *Advisory Information* Title: Multiple Vulnerabilities in TP-Link TL-SC3171 IP Cameras Advisory ID: CORE-2013-0618 Advisory URL: wwwcoresecuritycom/advisories/multiple-vulnerabilities-tp-link-tl-sc3171-ip-came ...
Core Security Technologies Advisory - TP-Link TL-SC3171 IP Cameras suffer from OS command injection, use of hard-coded credentials, authentication bypass, and missing authentication vulnerabilities ...