CVE-2020-12109

HIGHCVSS 8.8/10EPSS 74.34%

Last modified

CVE-2020-12109 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.. EPSS estimates a 74.34% chance of exploitation in the next 30 days.

Description

Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
74.34%

99.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
Tp-LinkNc200 Firmware2.1.6160108 B
Tp-LinkNc200 Firmware2.1.9200225
Tp-LinkNc210 Firmware1.0.3160229
Tp-LinkNc210 Firmware1.0.4160412
Tp-LinkNc210 Firmware1.0.9200304
Tp-LinkNc220 Firmware1.2.0170516
Tp-LinkNc220 Firmware1.3.0180105
Tp-LinkNc230 Firmware1.0.3160108
Tp-LinkNc230 Firmware1.2.1170515
Tp-LinkNc230 Firmware1.3.0200304
Tp-LinkNc250 Firmware1.0.8160108
Tp-LinkNc250 Firmware1.0.10160321
Tp-LinkNc250 Firmware1.2.1170515
Tp-LinkNc250 Firmware1.3.0200304
Tp-LinkNc260 Firmware1.0.5160804
Tp-LinkNc260 Firmware1.0.6161114
Tp-LinkNc260 Firmware1.4.1180720
Tp-LinkNc260 Firmware1.5.0181123
Tp-LinkNc260 Firmware1.5.2200304
Tp-LinkNc450 Firmware1.0.15160920
Tp-LinkNc450 Firmware1.1.2161013
Tp-LinkNc450 Firmware1.3.4171130
Tp-LinkNc450 Firmware1.5.3200304

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-12109?
Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.
How severe is CVE-2020-12109?
CVE-2020-12109 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 74.34% probability of exploitation in the next 30 days.
How do I fix CVE-2020-12109?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-12109?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST