PT-2013-3850 · Tp Link · Tp-Link Ip Cameras
Published
2013-10-11
·
Updated
2013-10-15
·
CVE-2013-2581
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
TP-Link IP Cameras versions prior to beta firmware LM.1.6.18P12 sign6
Description
The issue allows remote attackers to modify the firmware revision. This is achieved through the
cgi-bin/firmwareupgrade endpoint, by utilizing a "preset" action. The affected models include TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models.Recommendations
For versions prior to beta firmware LM.1.6.18P12 sign6, update to beta firmware LM.1.6.18P12 sign6 or later to resolve the issue. As a temporary workaround, consider restricting access to the
cgi-bin/firmwareupgrade endpoint to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tp-Link Ip Cameras