CVE-2020-13224

HIGHCVSS 8.8/10EPSS 2.18%

Last modified

CVE-2020-13224 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. TP-LINK NC200 devices through 2.1.10 build 200401, NC210 devices through 1.0.10 build 200401, NC220 devices through 1.3.1 build 200401, NC230 devices through 1.3.1 build 200401, NC250 devices through 1.3.1 build 200401, NC260 devices through 1.5.3 build_200401, and NC450 devices through 1.5.4 build 200401 have a Buffer Overflow. EPSS estimates a 2.18% chance of exploitation in the next 30 days.

Description

TP-LINK NC200 devices through 2.1.10 build 200401, NC210 devices through 1.0.10 build 200401, NC220 devices through 1.3.1 build 200401, NC230 devices through 1.3.1 build 200401, NC250 devices through 1.3.1 build 200401, NC260 devices through 1.5.3 build_200401, and NC450 devices through 1.5.4 build 200401 have a Buffer Overflow

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
2.18%

80.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Tp-LinkNc200 Firmware<= 2.1.10
Tp-LinkNc210 Firmware<= 1.0.10
Tp-LinkNc220 Firmware<= 1.3.1
Tp-LinkNc230 Firmware<= 1.3.1
Tp-LinkNc250 Firmware<= 1.3.1
Tp-LinkNc260 Firmware<= 1.5.3
Tp-LinkNc450 Firmware<= 1.5.4

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-13224?
TP-LINK NC200 devices through 2.1.10 build 200401, NC210 devices through 1.0.10 build 200401, NC220 devices through 1.3.1 build 200401, NC230 devices through 1.3.1 build 200401, NC250 devices through 1.3.1 build 200401, NC260 devices through 1.5.3 build_200401, and NC450 devices through 1.5.4 build 200401 have a Buffer Overflow
How severe is CVE-2020-13224?
CVE-2020-13224 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 2.18% probability of exploitation in the next 30 days.
How do I fix CVE-2020-13224?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-13224?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST