7.5
CVSSv3

CVE-2020-10231

Published: 01/04/2020 Updated: 12/05/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

TP-Link NC200 up to and including 2.1.8_Build_171109, NC210 up to and including 1.0.9_Build_171214, NC220 up to and including 1.3.0_Build_180105, NC230 up to and including 1.3.0_Build_171205, NC250 up to and including 1.3.0_Build_171205, NC260 up to and including 1.5.1_Build_190805, and NC450 up to and including 1.5.0_Build_181022 devices allow a remote NULL Pointer Dereference.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tp-link nc450 firmware 1.1.1

tp-link nc450 firmware 1.1.2

tp-link nc450 firmware 1.1.6

tp-link nc450 firmware 1.5.0

tp-link nc260 firmware 1.0.5

tp-link nc260 firmware 1.0.6

tp-link nc260 firmware 1.5.1

tp-link nc250 firmware 1.3.0

tp-link nc230 firmware 1.3.0

tp-link nc220 firmware 1.1.12

tp-link nc220 firmware 1.1.14

tp-link nc220 firmware 1.2.0

tp-link nc220 firmware 1.3.0

tp-link nc210 firmware 1.0.9

tp-link nc200 firmware 2.1.6

tp-link nc200 firmware 2.1.7

tp-link nc200 firmware 2.1.8

Mailing Lists

[UPDATE 08/04/2020] - The vendor has published firmware updates to fix the issue Vulnerability title: TP-LINK Cloud Cameras NCXXX Remote NULL Pointer Dereference Author: Pietro Oliva CVE: CVE-2020-10231 Vendor: TP-LINK Product: NC200, NC210, NC220, NC230, NC250, NC260, NC450 Affected version: NC200 <= 218 build 171109, NC210 <= 109 buil ...
Vulnerability title: TP-LINK Cloud Cameras NCXXX Remote NULL Pointer Dereference Author: Pietro Oliva CVE: CVE-2020-10231 Vendor: TP-LINK Product: NC200, NC210, NC220, NC230, NC250, NC260, NC450 Affected version: NC200 <= 218 build 171109, NC210 <= 109 build 171214, NC220 <= 130 build 180105, NC230 <= 130 build ...