CVE-2021-4045 is an unauthenticated Remote Code Execution (RCE) vulnerability affecting TP-Link Tapo C200 IP cameras running firmware version 1.1.15 and below. This critical flaw, with a CVSS score of 9.8, allows an attacker to gain full control of the camera without authentication due to a vulnerability in the root-privileged uhttpd binary. While not listed on the KEV catalog, an ExploitDB entry (EDB-51017) confirms exploit code availability, and the vulnerability has garnered significant community discussion and media coverage, including its use in the Beastmode botnet.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.1.15CPE matchmatch criteria | cpe:2.3:o:tp-link:tapo_c200_firmware:*:*:*:*:*:*:*:* | ||
>= 1.15, <= 1.15CPE match | cpe:2.3:h:tp-link:tapo_c200:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.