CVE-2020-12109
40Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 74%
from disclosure to weapon0 days
Published on NVDMay 4
metasploitApr 29
exploitation probability
74%top 1% of all CVEs
observed exploitation
nono source reports it
Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.
Affected products
n/a · n/a