TP-LINK Cloud Cameras NCXXX... CVE-2020-13224

9.0 AV AC AU C I A
发布: 2020-06-17
修订: 2024-11-21

``` TP-LINK Cloud Cameras NCXXX DelMultiUser Stack Overflow From: Pietro Oliva <pietroliva () gmail com> Date: Mon, 15 Jun 2020 21:18:15 +0100 Vulnerability title: TP-LINK Cloud Cameras NCXXX DelMultiUser Stack Overflow Author: Pietro Oliva CVE: CVE-2020-13224 Vendor: TP-LINK Product: NC200, NC210, NC220, NC230, NC250, NC260, NC450 Affected versions: NC200 <= 2.1.10 build 200401, NC210 <= 1.0.10 build 200401, NC220 <= 1.3.1 build 200401, NC230 <= 1.3.1 build 200401, NC250 <= 1.3.1 build 200401, NC260 <= 1.5.3 build_200401, NC450 <= 1.5.4 build 200401 Fixed versions: NC200 <= 2.1.11 build 200508, NC210 <= 1.0.11 build 200612, NC220 <= 1.3.2 build 200508, NC230 <= 1.3.2 build 200508, NC250 <= 1.3.2 build 200508, NC260 <= 1.5.4 build_200508, NC450 <= 1.5.5 build 200508 Description: The issue is located in the httpDelMultiUserRpm method of the ipcamera binary (Called when deleting multiple users via /delmultiuser.fcgi), where a comma-delimited list of usernames is passed as an input,...

0%
当前有1条漏洞利用/PoC
当前有14条受影响产品信息