TP-LINK Tapo C200 remote code execution vulnerability
97Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actcvss 9.8epss 72%
from disclosure to weapon0 days
Published on NVDMar 7
1st PoCNov 15
VulnCheck+25d
exploitation probability
72%top 1% of all CVEs
observed exploitation
yesVulnCheck
13 public exploit(s)
TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. The exploitation of this vulnerability allows an attacker to take full control of the camera.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
TP-Link · Tapo C200public PoCs found — 13
exploitdbwww.exploit-db.com/exploits/51017unverifiedgithubgithub.com/hacefresko/CVE-2021-4045★ 117githubgithub.com/0xbinder/CVE-2021-4045★ 9githubgithub.com/234329a423853/CVE-2021-4045★ 1githubgithub.com/DorskFR/tapodate★ 1githubgithub.com/jeffbezosispogg/CVE-2021-4045★ 1githubgithub.com/kaleth4/CVE-2021-4045★ 0vulncheckvulncheck.com/xdb/2dde4ee7c68cunverifiedvulncheckvulncheck.com/xdb/2bbb005b82beunverifiedvulncheckvulncheck.com/xdb/7d9531983dadunverifiedvulncheckvulncheck.com/xdb/ed0e050fe405unverifiedvulncheckvulncheck.com/xdb/d615a226dabaunverifiedcve_referencepacketstormsecurity.com/files/168472/TP-Link-Tapo-c200-1.1.15-Remote-Code-Execution.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.