peter bassill · operator
$ cve CVE-2021-4045 JSON

CVE-2021-4045 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 72.4% (pctl 99)

Patch early

A public exploit exists.

Description

TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. The exploitation of this vulnerability allows an attacker to take full control of the camera.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS72.38% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploityes
Published2022-03-10
Last modified2026-06-17

Affected (2)

VendorProduct
tp-linktapo c200
tp-linktapo c200 firmware

Public exploits

SourceTitleDate
exploit-dbTP-Link Tapo c200 1.1.15 - Remote Code Execution (RCE)2022-09-23

References

→ the Explorer  ·  watch your stack  ·  NVD