CVE-2020-11445
TP-Link
- Published
- 1 April 2020
- Last modified
- 17 June 2026
- CVSS
- 5.3 v3.1
- Severity
- medium
- EPSS
- 1.8% (77th pct)
- CISA KEV
- Not listed
- NVD status
- Modified
- Weaknesses
- None assigned
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Description
TP-Link cloud cameras through 2020-02-09 allow remote attackers to bypass authentication and obtain sensitive information via vectors involving a Wi-Fi session with GPS enabled, aka CNVD-2020-04855.
Exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalogue as of 2026.09.04. That is an absence of confirmed public exploitation, not evidence that exploitation has not occurred. EPSS models a 1.8% probability of exploitation activity in the next 30 days.
Affected products
| Product | Vendor | Type | Versions named |
|---|---|---|---|
| NC200 | TP-Link | unknown | 2.1.6, 2.1.7, 2.1.8, 2.1.9 +2 |
| NC210 | TP-Link | unknown | 1.0.3, 1.0.4, 1.0.9, <= 1.0.10 +1 |
| NC220 | TP-Link | unknown | 1.1.12, 1.1.14, 1.2.0, 1.3.0 +2 |
| NC230 | TP-Link | unknown | 1.0.3, 1.2.1, 1.3.0, <= 1.3.1 +1 |
| NC250 | TP-Link | unknown | 1.0.10, 1.0.8, 1.2.1, 1.3.0 +3 |
| NC260 | TP-Link | unknown | 1.0.5, 1.0.6, 1.4.1, 1.5.0 +4 |
| NC450 | TP-Link | unknown | 1.0.15, 1.1.1, 1.1.2, 1.1.6 +5 |
| Tapo C100 | TP-Link | unknown | 5.0, < 1.5.4, <= 1.1.15, <= 2020-02-09 |
| Tapo C200 | TP-Link | unknown | 1.0.12, 1.0.13, 1.0.17, 1.0.5 +24 |
| Tl-sc3430 | TP-Link | unknown | <= 2020-02-09 |
| Tl-sc3430n | TP-Link | unknown | <= 2020-02-09 |
| Tl-sc4171g | TP-Link | unknown | <= 2020-02-09 |
References
- https://www.cnvd.org.cn/flaw/show/1916613 third-party
- https://www.cnvd.org.cn/flaw/show/1916613 third-party
Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.