CVE-2021-4045
TP-LINK Tapo C200 remote code execution vulnerability
- Published
- Mar 7, 2022
- Updated
- Sep 17, 2024
- Assigning CNA
- INCIBE
- Evidence observed
- Sep 23, 2022
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.4%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. The exploitation of this vulnerability allows an attacker to take full control of the camera.
Sources
6- CVE-2021-4045Exploit
Exploit for command injection vulnerability found in uhttpd binary from TP-Link Tapo c200 IP camera
- CVE-2021-4045Exploit
🔐 "PWNTAPO: Unveiling Command Injection in TP-Link Tapo C200 Cameras (<= v1.1.16 Build 211209)" 🔓
- tapodateExploit
Sets up a local Tapo C200 using CVE-2021-4045
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.