Vulnerability Name:

CVE-2020-12110 (CCN-181258)

Assigned:2020-04-29
Published:2020-04-29
Updated:2020-05-12
Summary:Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.
CVSS v3 Severity:9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
5.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N)
5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.4 Medium (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-798
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2020-12110

Source: MISC
Type: Exploit, Third Party Advisory, VDB Entry
http://packetstormsecurity.com/files/157532/TP-LINK-Cloud-Cameras-NCXXX-Hardcoded-Encryption-Key.html

Source: XF
Type: UNKNOWN
tplink-cve202012110-info-disc(181258)

Source: CCN
Type: Packet Storm Security [05-01-2020]
TP-LINK Cloud Cameras NCXXX Hardcoded Encryption Key

Source: CCN
Type: Full-Disclosure Mailing List, Wed, 29 Apr 2020 23:44:43 +0100
TP-LINK Cloud Cameras NCXXX Hardcoded Encryption Key

Source: MISC
Type: Exploit, Mailing List, Third Party Advisory
https://seclists.org/fulldisclosure/2020/May/3

Source: CCN
Type: TP-Link Web site
NC series Cloud Cameras

Vulnerable Configuration:Configuration 1:
  • cpe:/o:tp-link:nc200_firmware:2.1.6:160108_b:*:*:*:*:*:*
  • OR cpe:/o:tp-link:nc200_firmware:2.1.9:200225:*:*:*:*:*:*
  • AND
  • cpe:/h:tp-link:nc200:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:tp-link:nc210_firmware:1.0.3:160229:*:*:*:*:*:*
  • OR cpe:/o:tp-link:nc210_firmware:1.0.4:160412:*:*:*:*:*:*
  • OR cpe:/o:tp-link:nc210_firmware:1.0.9:200304:*:*:*:*:*:*
  • AND
  • cpe:/h:tp-link:nc210:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:tp-link:nc220_firmware:1.2.0:170516:*:*:*:*:*:*
  • OR cpe:/o:tp-link:nc220_firmware:1.3.0:180105:*:*:*:*:*:*
  • OR cpe:/o:tp-link:nc220_firmware:1.3.0:200304:*:*:*:*:*:*
  • AND
  • cpe:/h:tp-link:nc220:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:tp-link:nc230_firmware:1.0.3:160108:*:*:*:*:*:*
  • OR cpe:/o:tp-link:nc230_firmware:1.2.1:170515:*:*:*:*:*:*
  • OR cpe:/o:tp-link:nc230_firmware:1.3.0:200304:*:*:*:*:*:*
  • AND
  • cpe:/h:tp-link:nc230:-:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:tp-link:nc250_firmware:1.0.8:160108:*:*:*:*:*:*
  • OR cpe:/o:tp-link:nc250_firmware:1.0.10:160321:*:*:*:*:*:*
  • OR cpe:/o:tp-link:nc250_firmware:1.2.1:170515:*:*:*:*:*:*
  • OR cpe:/o:tp-link:nc250_firmware:1.3.0:200304:*:*:*:*:*:*
  • AND
  • cpe:/h:tp-link:nc250:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:tp-link:nc260_firmware:1.0.5:160804:*:*:*:*:*:*
  • OR cpe:/o:tp-link:nc260_firmware:1.0.6:161114:*:*:*:*:*:*
  • OR cpe:/o:tp-link:nc260_firmware:1.4.1:180720:*:*:*:*:*:*
  • OR cpe:/o:tp-link:nc260_firmware:1.5.0:181123:*:*:*:*:*:*
  • OR cpe:/o:tp-link:nc260_firmware:1.5.2:200304:*:*:*:*:*:*
  • AND
  • cpe:/h:tp-link:nc260:-:*:*:*:*:*:*:*

  • Configuration 7:
  • cpe:/o:tp-link:nc450_firmware:1.0.15:160920:*:*:*:*:*:*
  • OR cpe:/o:tp-link:nc450_firmware:1.1.2:161013:*:*:*:*:*:*
  • OR cpe:/o:tp-link:nc450_firmware:1.3.4:171130:*:*:*:*:*:*
  • OR cpe:/o:tp-link:nc450_firmware:1.5.3:200304:*:*:*:*:*:*
  • AND
  • cpe:/h:tp-link:nc450:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    tp-link nc200 firmware 2.1.6 160108_b
    tp-link nc200 firmware 2.1.9 200225
    tp-link nc200 -
    tp-link nc210 firmware 1.0.3 160229
    tp-link nc210 firmware 1.0.4 160412
    tp-link nc210 firmware 1.0.9 200304
    tp-link nc210 -
    tp-link nc220 firmware 1.2.0 170516
    tp-link nc220 firmware 1.3.0 180105
    tp-link nc220 firmware 1.3.0 200304
    tp-link nc220 -
    tp-link nc230 firmware 1.0.3 160108
    tp-link nc230 firmware 1.2.1 170515
    tp-link nc230 firmware 1.3.0 200304
    tp-link nc230 -
    tp-link nc250 firmware 1.0.8 160108
    tp-link nc250 firmware 1.0.10 160321
    tp-link nc250 firmware 1.2.1 170515
    tp-link nc250 firmware 1.3.0 200304
    tp-link nc250 -
    tp-link nc260 firmware 1.0.5 160804
    tp-link nc260 firmware 1.0.6 161114
    tp-link nc260 firmware 1.4.1 180720
    tp-link nc260 firmware 1.5.0 181123
    tp-link nc260 firmware 1.5.2 200304
    tp-link nc260 -
    tp-link nc450 firmware 1.0.15 160920
    tp-link nc450 firmware 1.1.2 161013
    tp-link nc450 firmware 1.3.4 171130
    tp-link nc450 firmware 1.5.3 200304
    tp-link nc450 -