peter bassill · operator
$ cve CVE-2020-12110 JSON

CVE-2020-12110

9.8
CRITICAL · CVSS 3.1 · EPSS 13.6% (pctl 96)

Patch early

EPSS 13.6% — above the 10% action threshold.

Description

Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS13.57% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-798
On CISA KEVno
Public exploitnone known
Published2020-05-04
Last modified2026-06-17

Affected (14)

VendorProduct
tp-linknc200
tp-linknc200 firmware
tp-linknc210
tp-linknc210 firmware
tp-linknc220
tp-linknc220 firmware
tp-linknc230
tp-linknc230 firmware
tp-linknc250
tp-linknc250 firmware
tp-linknc260
tp-linknc260 firmware
tp-linknc450
tp-linknc450 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD