CVE-2013-2579 describes a critical vulnerability in several TP-Link IP Camera models (TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and potentially others) with firmware older than LM.1.6.18P12_sign6. This flaw allows remote attackers to gain administrative access via TELNET due to a hardcoded "qmik" account having an empty password. With a CVSS score of 10.0, this vulnerability is highly severe, enabling complete compromise of confidentiality, integrity, and availability with no authentication required. While not listed on the KEV catalog, public exploit code is available, and despite its age, the EPSS score suggests a non-negligible probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:tp-link:tl-sc3130:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:tp-link:tl-sc3130g:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:tp-link:tl-sc3171:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:h:tp-link:tl-sc3171g:-:*:*:*:*:*:*:* | ||
<= 1.6.18p12_sign5CPE matchmatch criteria | cpe:2.3:o:tp-link:lm_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.