← Vulnerability feed

Vulnerability record · CVE-2020-12109 · published 4 May 2020

CVE-2020-12109: TP-Link NC-series cloud cameras command injection via Bonjour

Tp Link · Nc200 Firmware

TP-Link NC200, NC210, NC220, NC230, NC250, NC260 and NC450 cloud cameras contain an OS command injection flaw (CWE-78) reachable over the network. The record names specific affected firmware builds but gives no further technical detail on the injection point beyond the Bonjour-related exploit references. Successful exploitation gives full compromise of the camera's confidentiality, integrity and availability.

8.8 CVSS 3.1 High EPSS 74% · top 0.5% CWE-78 · OS command injection
8.8CVSS 3.1 base score, v2 9.0
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
7Affected product versions listed by NVD
8References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityNetwork-reachable command injection with public exploit code and a very high EPSS score, though it requires low privileges and is not in KEV.

What it is

TP-Link NC200, NC210, NC220, NC230, NC250, NC260 and NC450 cloud cameras contain an OS command injection flaw (CWE-78) reachable over the network. The record names specific affected firmware builds but gives no further technical detail on the injection point beyond the Bonjour-related exploit references. Successful exploitation gives full compromise of the camera's confidentiality, integrity and availability.

Impact

An attacker can execute arbitrary OS commands on the device, gaining full control of the camera and any data or network access it holds. With C:H/I:H/A:H, the impact spans data theft, tampering and denial of service.

Attack surface

Reachable over the network (AV:N) with low attack complexity and no user interaction; the CVSS vector requires low privileges (PR:L), so some level of access or authentication is needed. The exploit references point to the Bonjour service as the injection vector.

Exploitation

Not listed in CISA KEV, but EPSS is very high at 0.743 (99.5th percentile) and multiple references are tagged Exploit, including Packet Storm and Full Disclosure postings, indicating public exploit code exists.

What to do

  • Apply the vendor firmware update from TP-Link's security page for the affected NC-series models; patch is the first action.
  • If no fix is available for a model, isolate the camera on a segmented VLAN with no access to trusted hosts.
  • Disable or block the Bonjour/mDNS service on the camera and at the network boundary where operationally possible.
  • Restrict management and service access to trusted IPs and change default credentials to limit the low-privilege foothold the vector assumes.
  • Monitor vendor advisories for updated firmware builds covering the listed versions.

Detection

  • Alert on unexpected outbound connections or command-shell-like traffic from camera VLANs.
  • Monitor for anomalous mDNS/Bonjour traffic or malformed Bonjour responses involving NC-series devices.
  • Baseline camera process and network behavior and flag new processes, listeners or outbound sessions.
  • Review authentication and access logs on the cameras for unexpected low-privilege logins preceding suspicious activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

7 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-12109 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-12110Tp-link nc200 firmware hard-coded credentials vulnerabilityCertain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC…EPSS 14%8.8CVE-2020-13224Tp-link nc200 firmware classic buffer overflow vulnerabilityTP-LINK NC200 devices through 2.1.10 build 200401, NC210 devices through 1.0.10 build 200401, NC220 devices through 1.3.1 build 200401, NC230 devices…EPSS 2.2%7.5CVE-2020-10231Tp-link nc450 firmware null pointer dereference vulnerabilityTP-Link NC200 through 2.1.8_Build_171109, NC210 through 1.0.9_Build_171214, NC220 through 1.3.0_Build_180105, NC230 through 1.3.0_Build_171205, NC250…EPSS 3.8%6.5CVE-2017-10796Tp-link nc250 firmware improper authentication vulnerabilityOn TP-Link NC250 devices with firmware through 1.2.1 build 170515, anyone can view video and audio without authentication via an rtsp://admin@yourip:…EPSS 0.95%5.3CVE-2020-11445Tp-link nc450 firmware vulnerabilityTP-Link cloud cameras through 2020-02-09 allow remote attackers to bypass authentication and obtain sensitive information via vectors involving a Wi-…EPSS 1.8%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed

Source: NIST National Vulnerability Database (record CVE-2020-12109), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.