Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Certain TP-Link devices allow Command Injection. This affects NC260 1.5.2 build 200304 and NC450 1.5.3 build 200304.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TP-Link NC260和NC450 操作系统命令注入漏洞
Vulnerability Description
TP-Link NC260和TP-Link NC450都是中国普联(TP-Link)公司的一款网络摄像头。 TP-Link NC260 1.5.2 build 200304版本和NC450 1.5.3 build 200304版本中的ipcamera二进制文件的httpSetEncryptKeyRpm方法存在操作系统命令注入漏洞。远程攻击者可通过发送特制HTTP POST请求到setEncryptKey.fcgi脚本利用该漏洞以root用户身份在系统上执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A