HIGH · 8.8

CVE-2020-13224

TP-LINK NC200 devices through 2.1.10 build 200401, NC210 devices through 1.0.10 build 200401, NC220 devices through 1.3.1 build 200401, NC230 devices through 1.3.1 build 200401, NC250 devices through ...

Vulnerability Description

TP-LINK NC200 devices through 2.1.10 build 200401, NC210 devices through 1.0.10 build 200401, NC220 devices through 1.3.1 build 200401, NC230 devices through 1.3.1 build 200401, NC250 devices through 1.3.1 build 200401, NC260 devices through 1.5.3 build_200401, and NC450 devices through 1.5.4 build 200401 have a Buffer Overflow

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Tp-LinkNc200 Firmware<= 2.1.10
Tp-LinkNc200-
Tp-LinkNc210 Firmware<= 1.0.10
Tp-LinkNc210-
Tp-LinkNc220 Firmware<= 1.3.1
Tp-LinkNc220-
Tp-LinkNc230 Firmware<= 1.3.1
Tp-LinkNc230-
Tp-LinkNc250 Firmware<= 1.3.1
Tp-LinkNc250-
Tp-LinkNc260 Firmware<= 1.5.3
Tp-LinkNc260-
Tp-LinkNc450 Firmware<= 1.5.4
Tp-LinkNc450-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-13224?

CVE-2020-13224 is a vulnerability with a CVSS score of 8.8 (HIGH). TP-LINK NC200 devices through 2.1.10 build 200401, NC210 devices through 1.0.10 build 200401, NC220 devices through 1.3.1 build 200401, NC230 devices through 1.3.1 build 200401, NC250 devices through ...

How severe is CVE-2020-13224?

CVE-2020-13224 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-13224?

Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Nc200 Firmware, Tp-Link Nc200, Tp-Link Nc210 Firmware, Tp-Link Nc210, Tp-Link Nc220 Firmware.