CameraRisk

CVE-2020-11445

TP-Link

Published
1 April 2020
Last modified
17 June 2026
CVSS
5.3 v3.1
Severity
medium
EPSS
1.8% (77th pct)
CISA KEV
Not listed
NVD status
Modified
Weaknesses
None assigned

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Description

TP-Link cloud cameras through 2020-02-09 allow remote attackers to bypass authentication and obtain sensitive information via vectors involving a Wi-Fi session with GPS enabled, aka CNVD-2020-04855.

Exploitation

Not listed in the CISA Known Exploited Vulnerabilities catalogue as of 2026.09.04. That is an absence of confirmed public exploitation, not evidence that exploitation has not occurred. EPSS models a 1.8% probability of exploitation activity in the next 30 days.

Affected products

ProductVendorTypeVersions named
NC200 TP-Link unknown 2.1.6, 2.1.7, 2.1.8, 2.1.9 +2
NC210 TP-Link unknown 1.0.3, 1.0.4, 1.0.9, <= 1.0.10 +1
NC220 TP-Link unknown 1.1.12, 1.1.14, 1.2.0, 1.3.0 +2
NC230 TP-Link unknown 1.0.3, 1.2.1, 1.3.0, <= 1.3.1 +1
NC250 TP-Link unknown 1.0.10, 1.0.8, 1.2.1, 1.3.0 +3
NC260 TP-Link unknown 1.0.5, 1.0.6, 1.4.1, 1.5.0 +4
NC450 TP-Link unknown 1.0.15, 1.1.1, 1.1.2, 1.1.6 +5
Tapo C100 TP-Link unknown 5.0, < 1.5.4, <= 1.1.15, <= 2020-02-09
Tapo C200 TP-Link unknown 1.0.12, 1.0.13, 1.0.17, 1.0.5 +24
Tl-sc3430 TP-Link unknown <= 2020-02-09
Tl-sc3430n TP-Link unknown <= 2020-02-09
Tl-sc4171g TP-Link unknown <= 2020-02-09

References

CVE-2020-11445 at NVD

Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.