This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Tp-Link First view 2020-04-01
Product nc260 Firmware Last view 2020-06-17
Version Type Os
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:o:tp-link:nc260_firmware:1.0.5:160804:*:*:*:*:*:* 6
cpe:2.3:o:tp-link:nc260_firmware:1.0.6:161114:*:*:*:*:*:* 6
cpe:2.3:o:tp-link:nc260_firmware:1.4.1:180720:*:*:*:*:*:* 5
cpe:2.3:o:tp-link:nc260_firmware:1.5.0:181123:*:*:*:*:*:* 5
cpe:2.3:o:tp-link:nc260_firmware:1.5.2:200304:*:*:*:*:*:* 5
cpe:2.3:o:tp-link:nc260_firmware:1.5.1:190805:*:*:*:*:*:* 3

Related : CVE

  Date Alert Description
8.8 2020-06-17 CVE-2020-13224

TP-LINK NC200 devices through 2.1.10 build 200401, NC210 devices through 1.0.10 build 200401, NC220 devices through 1.3.1 build 200401, NC230 devices through 1.3.1 build 200401, NC250 devices through 1.3.1 build 200401, NC260 devices through 1.5.3 build_200401, and NC450 devices through 1.5.4 build 200401 have a Buffer Overflow

8.8 2020-05-04 CVE-2020-12111

Certain TP-Link devices allow Command Injection. This affects NC260 1.5.2 build 200304 and NC450 1.5.3 build 200304.

9.8 2020-05-04 CVE-2020-12110

Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.

8.8 2020-05-04 CVE-2020-12109

Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.

5.3 2020-04-01 CVE-2020-11445

TP-Link cloud cameras through 2020-02-09 allow remote attackers to bypass authentication and obtain sensitive information via vectors involving a Wi-Fi session with GPS enabled, aka CNVD-2020-04855.

7.5 2020-04-01 CVE-2020-10231

TP-Link NC200 through 2.1.8_Build_171109, NC210 through 1.0.9_Build_171214, NC220 through 1.3.0_Build_180105, NC230 through 1.3.0_Build_171205, NC250 through 1.3.0_Build_171205, NC260 through 1.5.1_Build_190805, and NC450 through 1.5.0_Build_181022 devices allow a remote NULL Pointer Dereference.

CWE : Common Weakness Enumeration

%idName
40% (2) CWE-78 Improper Sanitization of Special Elements used in an OS Command ('O...
20% (1) CWE-798 Use of Hard-coded Credentials
20% (1) CWE-476 NULL Pointer Dereference
20% (1) CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflo...

Snort® IPS/IDS

Date Description
2020-07-07 TP-LINK Cloud Cameras NCXXX Bonjour command injection attempt
RuleID : 54198 - Type : SERVER-WEBAPP - Revision : 1
2020-07-07 TP-LINK Cloud Cameras NCXXX Bonjour command injection attempt
RuleID : 54197 - Type : SERVER-WEBAPP - Revision : 1
2020-07-07 TP-LINK Cloud Cameras NCXXX Bonjour command injection attempt
RuleID : 54196 - Type : SERVER-WEBAPP - Revision : 1
2020-07-07 TP-LINK Cloud Cameras NCXXX Bonjour command injection attempt
RuleID : 54195 - Type : SERVER-WEBAPP - Revision : 1