HTTP: TP-Link NC2XX OS Command Injection

This signature detects attempts to exploit a known vulnerability against TP Link. A successful attack can lead to arbitrary code execution.

Extended Description

Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.

References

CVE: CVE-2020-12109

Short Name
HTTP:CTS:TP-LINK-OS-CMD-INJ
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2020-12109 Command Injection NC2XX OS TP-Link
Release Date
01/06/2022
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3805
False Positive
Unknown
CVSS Score

9.0

Found a potential security threat?