← Advisories

TP-Link NC200/NC220 Cloud Camera 300Mbps Wi-Fi Hard-Coded Credentials

High
Advisory ID
ZSL-2015-5255
Release Date
14 September 2015
Vendor
TP-LINK Technologies Co., Ltd. - http://www.tp-link.us
Affected Version
NC220 V1 1.0.28 Build 150629 Rel.22346, NC200 V1 2.0.15 Build 150701 Rel.20962
CVE
N/A
Tested On
Linux
Summary

Designed with simplicity in mind, TP-LINK's Cloud Cameras are a fast and trouble free way to keep track on what's going on in and around your home. Video monitoring, recording and sharing has never been easier with the use of TP-LINK’s Cloud service. The excitement of possibilities never end.

Description

NC220 and NC200 utilizes hard-coded credentials within its Linux distribution image. These sets of credentials (root:root) are never exposed to the end-user and cannot be changed through any normal operation of the camera.

Proof of Concept
Disclosure Timeline
N/A
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
14.09.2015Initial release
17.09.2015Added reference [1], [2], [3] and [4]