Vulnerability record · CVE-2013-2578 · published 11 October 2013
CVE-2013-2578: TP-Link IP Cameras servetest CGI command injection
Tp Link · Tl Sc3130
The cgi-bin/admin/servetest endpoint in several TP-Link IP camera models passes user-supplied parameters such as ServerName to a shell without sanitization, allowing OS command injection. Because the endpoint is reachable over the network without authentication, any host that can reach the camera can run arbitrary commands as the device's web user.
Description
cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the ServerName parameter and (2) other unspecified parameters.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote command execution with a CVSS 2.0 score of 10 and very high EPSS, though the product is old and no KEV listing exists.
What it is
The cgi-bin/admin/servetest endpoint in several TP-Link IP camera models passes user-supplied parameters such as ServerName to a shell without sanitization, allowing OS command injection. Because the endpoint is reachable over the network without authentication, any host that can reach the camera can run arbitrary commands as the device's web user.
Impact
An attacker gains arbitrary command execution on the camera, enabling full compromise of the device, including access to video streams, credentials and any network reachable from the camera.
Attack surface
Reached over the network via HTTP requests to cgi-bin/admin/servetest; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.737, 99.4th percentile) and both references are tagged Exploit, indicating public exploit material exists.
What to do
- Apply the vendor beta firmware LM.1.6.18P12_sign6 or later for affected TL-SC3130/3130G/3171/3171G models.
- If patching is not possible, block or restrict access to cgi-bin/admin/servetest and the camera web interface from untrusted networks.
- Place cameras on an isolated VLAN with no outbound internet access and strict firewall rules.
- Replace end-of-life camera models that no longer receive firmware updates.
- Change default credentials and disable unused services on the camera.
Detection
- Monitor HTTP requests to /cgi-bin/admin/servetest, especially those containing shell metacharacters in parameters such as ServerName.
- Alert on unexpected outbound connections or processes spawned by the camera's web service.
- Review camera logs for anomalous requests to admin CGI endpoints from unfamiliar source IPs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-2578 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-2578), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.