← Back to CVE List
Vulnerability Intelligence Report

CVE-2013-2578

cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the ServerName parameter and (2) other unspecified parameters.

No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:73.71%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
tp-link tl-sc3130 all
tp-link tl-sc3130g all
tp-link tl-sc3171 all
tp-link tl-sc3171g all
tp-link lm_firmware all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
73.713%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2013-03-15T00:00:00
Published2013-10-11T21:00:00
Last Updated2024-09-16T20:47:22

LINK COPIED TO CLIPBOARD