Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-20078
HistoryMar 14, 2022 - 12:00 a.m.

Tp-link Tapo C200 Command Injection Vulnerability

2022-03-1400:00:00
China National Vulnerability Database
www.cnvd.org.cn
45
tp-link
tapo c200
command injection
vulnerability
firmware
uhttpd
binary file
root access
unauthenticated attacker
system commands
security issue

EPSS

0.251

Percentile

96.7%

A command injection vulnerability exists in Tp-link Tapo C200 1.1.15 and previous firmware versions, which is caused by the presence of a uhttpd binary file that runs as root by default and lacks filtering and escaping. An unauthenticated attacker could use this vulnerability to execute system commands on the system via special command requests.