CVE-2020-13224
Severity CVSS v4.0:
Pending analysis
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
17/06/2020
Last modified:
24/06/2020
Description
TP-LINK NC200 devices through 2.1.10 build 200401, NC210 devices through 1.0.10 build 200401, NC220 devices through 1.3.1 build 200401, NC230 devices through 1.3.1 build 200401, NC250 devices through 1.3.1 build 200401, NC260 devices through 1.5.3 build_200401, and NC450 devices through 1.5.4 build 200401 have a Buffer Overflow
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
9.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:tp-link:nc200_firmware:*:*:*:*:*:*:*:* | 2.1.10 (including) | |
| cpe:2.3:h:tp-link:nc200:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:nc210_firmware:*:*:*:*:*:*:*:* | 1.0.10 (including) | |
| cpe:2.3:h:tp-link:nc210:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:nc220_firmware:*:*:*:*:*:*:*:* | 1.3.1 (including) | |
| cpe:2.3:h:tp-link:nc220:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:nc230_firmware:*:*:*:*:*:*:*:* | 1.3.1 (including) | |
| cpe:2.3:h:tp-link:nc230:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:nc250_firmware:*:*:*:*:*:*:*:* | 1.3.1 (including) | |
| cpe:2.3:h:tp-link:nc250:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:nc260_firmware:*:*:*:*:*:*:*:* | 1.5.3 (including) | |
| cpe:2.3:h:tp-link:nc260:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:tp-link:nc450_firmware:*:*:*:*:*:*:*:* | 1.5.4 (including) | |
| cpe:2.3:h:tp-link:nc450:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



