← Vulnerability feed

Vulnerability record · CVE-2013-2578 · published 11 October 2013

CVE-2013-2578: TP-Link IP Cameras servetest CGI command injection

Tp Link · Tl Sc3130

The cgi-bin/admin/servetest endpoint in several TP-Link IP camera models passes user-supplied parameters such as ServerName to a shell without sanitization, allowing OS command injection. Because the endpoint is reachable over the network without authentication, any host that can reach the camera can run arbitrary commands as the device's web user.

10.0 CVSS 2.0 High EPSS 74% · top 0.5% CWE-78 · OS command injection
10.0CVSS 2.0 base score
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
2References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the ServerName parameter and (2) other unspecified parameters.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote command execution with a CVSS 2.0 score of 10 and very high EPSS, though the product is old and no KEV listing exists.

What it is

The cgi-bin/admin/servetest endpoint in several TP-Link IP camera models passes user-supplied parameters such as ServerName to a shell without sanitization, allowing OS command injection. Because the endpoint is reachable over the network without authentication, any host that can reach the camera can run arbitrary commands as the device's web user.

Impact

An attacker gains arbitrary command execution on the camera, enabling full compromise of the device, including access to video streams, credentials and any network reachable from the camera.

Attack surface

Reached over the network via HTTP requests to cgi-bin/admin/servetest; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.737, 99.4th percentile) and both references are tagged Exploit, indicating public exploit material exists.

What to do

  • Apply the vendor beta firmware LM.1.6.18P12_sign6 or later for affected TL-SC3130/3130G/3171/3171G models.
  • If patching is not possible, block or restrict access to cgi-bin/admin/servetest and the camera web interface from untrusted networks.
  • Place cameras on an isolated VLAN with no outbound internet access and strict firewall rules.
  • Replace end-of-life camera models that no longer receive firmware updates.
  • Change default credentials and disable unused services on the camera.

Detection

  • Monitor HTTP requests to /cgi-bin/admin/servetest, especially those containing shell metacharacters in parameters such as ServerName.
  • Alert on unexpected outbound connections or processes spawned by the camera's web service.
  • Review camera logs for anomalous requests to admin CGI endpoints from unfamiliar source IPs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-2578 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-2579Tp-link tl-sc3130 vulnerabilityTP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 have an empty pass…EPSS 3.7%7.8CVE-2013-2581Tp-link tl-sc3130 permissions and access controls vulnerabilitycgi-bin/firmwareupgrade in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P…EPSS 2.4%7.1CVE-2013-2580Tp-link tl-sc3130 vulnerabilityUnrestricted file upload vulnerability in cgi-bin/uploadfile in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other m…EPSS 3.5%7.1CVE-2013-3688Tp-link tl-sc3130 permissions and access controls vulnerabilityThe TP-Link IP Cameras TL-SC3171, TL-SC3130, TL-SC3130G, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6, does not prop…EPSS 1.3%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed7.8CVE-2026-83549SonicWall SMA1000 AMC OS Command InjectionThe SMA1000 Appliance Management Console contains an OS command injection flaw (CWE-78) that lets an authenticated administrator execute arbitrary op…KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2013-2578), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.