← back
CVE-2021-4045criticalobserved exploitationCWE-77

TP-LINK Tapo C200 remote code execution vulnerability

97Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.

ssvc Actcvss 9.8epss 72%
from disclosure to weapon0 days
Published on NVDMar 7
1st PoCNov 15
VulnCheck+25d
exploitation probability
72%top 1% of all CVEs
observed exploitation
yesVulnCheck
13 public exploit(s)
TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. The exploitation of this vulnerability allows an attacker to take full control of the camera.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
TP-Link · Tapo C200
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.