PT-2020-7396 · Tp Link · Tp-Link Ip Cameras Tl-Sc 3130+2

Published

2020-01-29

·

Updated

2020-01-31

·

CVE-2013-2572

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: TP-LINK IP Cameras TL-SC 3130 version 1.6.18P12 TP-LINK IP Cameras TL-SC 3130G TP-LINK IP Cameras 3171G TP-LINK IP Cameras 4171G
Description: A Security Bypass issue exists due to default hard-coded credentials for the administrative Web interface, which could let a malicious user obtain unauthorized access to CGI files.
Recommendations: For TP-LINK IP Cameras TL-SC 3130 version 1.6.18P12, consider changing the default administrative credentials to prevent unauthorized access. For TP-LINK IP Cameras TL-SC 3130G, 3171G, and 4171G, change the default hard-coded credentials for the administrative Web interface to mitigate the risk of exploitation. As a temporary workaround, restrict access to the administrative Web interface until a fix is applied.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-2572

Affected Products

Tp-Link Ip Cameras 3171G
Tp-Link Ip Cameras 4171G
Tp-Link Ip Cameras Tl-Sc 3130