CVE-2013-2580 Information

Description

Unrestricted file upload vulnerability in cgi-bin/uploadfile in TP-Link IP Cameras TL-SC3130 TL-SC3130G TL-SC3171 TL-SC3171G and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to upload arbitrary files then accessing it via a direct request to the file in the mnt/mtd directory.

Reference

http://www.coresecurity.com/advisories/multiple-vulnerabilities-tp-link-tl-sc3171-ip-cameras

Share on: