CVE-2021-4045 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 72.4% (pctl 99)
Patch early
A public exploit exists.
Description
TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. The exploitation of this vulnerability allows an attacker to take full control of the camera.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 72.38% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-77 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2022-03-10 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| tp-link | tapo c200 |
| tp-link | tapo c200 firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | TP-Link Tapo c200 1.1.15 - Remote Code Execution (RCE) | 2022-09-23 |
References
- http://packetstormsecurity.com/files/168472/TP-Link-Tapo-c200-1.1.15-Remote-Code-Execution.html
- https://www.incibe-cert.es/en/early-warning/security-advisories/tp-link-tapo-c200-remote-code-execution-vulnerability
- http://packetstormsecurity.com/files/168472/TP-Link-Tapo-c200-1.1.15-Remote-Code-Execution.html
- https://www.incibe-cert.es/en/early-warning/security-advisories/tp-link-tapo-c200-remote-code-execution-vulnerability
→ the Explorer · watch your stack · NVD