CRITICAL

CVE-2021-4045

CVSS v3

9.8

CRITICAL

EPSS Score

89.4%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. The exploitation of this vulnerability allows an attacker to take full control of the camera.

Technical details

Published
3/10/2022
Exploit-DB
EDB-51017

Frequently asked questions

What is CVE-2021-4045?

TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. The exploitation of this vulnerability allows an attacker to take full control of the camera.

Is CVE-2021-4045 actively exploited?

Active exploitation of CVE-2021-4045 has not been confirmed. The EPSS score is 89.4%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-4045?

CVE-2021-4045 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2021-4045 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.