CVE-2020-11445

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/04/2020
Last modified:
21/07/2021

Description

TP-Link cloud cameras through 2020-02-09 allow remote attackers to bypass authentication and obtain sensitive information via vectors involving a Wi-Fi session with GPS enabled, aka CNVD-2020-04855.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tp-link:nc450_firmware:*:*:*:*:*:*:*:* 2020-02-09 (including)
cpe:2.3:h:tp-link:nc450:-:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:nc260_firmware:*:*:*:*:*:*:*:* 2020-02-09 (including)
cpe:2.3:h:tp-link:nc260:-:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:nc250_firmware:*:*:*:*:*:*:*:* 2020-02-09 (including)
cpe:2.3:h:tp-link:nc250:-:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:nc230_firmware:*:*:*:*:*:*:*:* 2020-02-09 (including)
cpe:2.3:h:tp-link:nc230:-:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:nc220_firmware:*:*:*:*:*:*:*:* 2020-02-09 (including)
cpe:2.3:h:tp-link:nc220:-:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:nc210_firmware:*:*:*:*:*:*:*:* 2020-02-09 (including)
cpe:2.3:h:tp-link:nc210:-:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:nc200_firmware:*:*:*:*:*:*:*:* 2020-02-09 (including)
cpe:2.3:h:tp-link:nc200:-:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:kc300s2_firmware:*:*:*:*:*:*:*:* 2020-02-09 (including)


References to Advisories, Solutions, and Tools