Vulnerability record · CVE-2020-12109 · published 4 May 2020
CVE-2020-12109: TP-Link NC-series cloud cameras command injection via Bonjour
Tp Link · Nc200 Firmware
TP-Link NC200, NC210, NC220, NC230, NC250, NC260 and NC450 cloud cameras contain an OS command injection flaw (CWE-78) reachable over the network. The record names specific affected firmware builds but gives no further technical detail on the injection point beyond the Bonjour-related exploit references. Successful exploitation gives full compromise of the camera's confidentiality, integrity and availability.
Description
Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityNetwork-reachable command injection with public exploit code and a very high EPSS score, though it requires low privileges and is not in KEV.
What it is
TP-Link NC200, NC210, NC220, NC230, NC250, NC260 and NC450 cloud cameras contain an OS command injection flaw (CWE-78) reachable over the network. The record names specific affected firmware builds but gives no further technical detail on the injection point beyond the Bonjour-related exploit references. Successful exploitation gives full compromise of the camera's confidentiality, integrity and availability.
Impact
An attacker can execute arbitrary OS commands on the device, gaining full control of the camera and any data or network access it holds. With C:H/I:H/A:H, the impact spans data theft, tampering and denial of service.
Attack surface
Reachable over the network (AV:N) with low attack complexity and no user interaction; the CVSS vector requires low privileges (PR:L), so some level of access or authentication is needed. The exploit references point to the Bonjour service as the injection vector.
Exploitation
Not listed in CISA KEV, but EPSS is very high at 0.743 (99.5th percentile) and multiple references are tagged Exploit, including Packet Storm and Full Disclosure postings, indicating public exploit code exists.
What to do
- Apply the vendor firmware update from TP-Link's security page for the affected NC-series models; patch is the first action.
- If no fix is available for a model, isolate the camera on a segmented VLAN with no access to trusted hosts.
- Disable or block the Bonjour/mDNS service on the camera and at the network boundary where operationally possible.
- Restrict management and service access to trusted IPs and change default credentials to limit the low-privilege foothold the vector assumes.
- Monitor vendor advisories for updated firmware builds covering the listed versions.
Detection
- Alert on unexpected outbound connections or command-shell-like traffic from camera VLANs.
- Monitor for anomalous mDNS/Bonjour traffic or malformed Bonjour responses involving NC-series devices.
- Baseline camera process and network behavior and flag new processes, listeners or outbound sessions.
- Review authentication and access logs on the cameras for unexpected low-privilege logins preceding suspicious activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/157531/TP-LINK-Cloud-Cameras-NCXXX-Bonjour-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/159222/TP-Link-Cloud-Cameras-NCXXX-Bonjour-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://seclists.org/fulldisclosure/2020/May/2 | ExploitMailing ListThird Party Advisory |
| https://www.tp-link.com/us/security | Vendor Advisory |
| http://packetstormsecurity.com/files/157531/TP-LINK-Cloud-Cameras-NCXXX-Bonjour-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/159222/TP-Link-Cloud-Cameras-NCXXX-Bonjour-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://seclists.org/fulldisclosure/2020/May/2 | ExploitMailing ListThird Party Advisory |
| https://www.tp-link.com/us/security | Vendor Advisory |
Track CVE-2020-12109 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-12109), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.