CVE-2020-12110
Status: ModifiedCritical (9.8)—
Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Base score: 9.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 14%
- Percentile among all scored CVEs: 96
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (7)
CWEs
- CWE-798
References
Raw JSON (NVD)
Show
{
"id": "CVE-2020-12110",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2020-05-04T14:15:13.277",
"references": [
{
"url": "http://packetstormsecurity.com/files/157532/TP-LINK-Cloud-Cameras-NCXXX-Hardcoded-Encryption-Key.html",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "https://seclists.org/fulldisclosure/2020/May/3",
"tags": [
"Exploit",
"Mailing List",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://packetstormsecurity.com/files/157532/TP-LINK-Cloud-Cameras-NCXXX-Hardcoded-Encryption-Key.html",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://seclists.org/fulldisclosure/2020/May/3",
"tags": [
"Exploit",
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-798"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Certain TP-Link devices have a Hardcoded Encryption Key. This affects NC200 2.1.9 build 200225, N210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build 200304."
},
{
"lang": "es",
"value": "Determinados dispositivos TP-Link tienen una Clave de Cifrado Embebida. Esto afecta a NC200 versión 2.1.9 build 200225, N210 versión 1.0.9 build 200304, NC220 versión 1.3.0 build 200304, NC230 versión 1.3.0 build 200304, NC250 versión 1.3.0 build 200304, NC260 versión 1.5.2 build 200304, y NC450 versión 1.5.3 build 200304."
}
],
"lastModified": "2026-06-17T02:51:25.343",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:nc200_firmware:2.1.6:160108_b:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C49E1583-39DF-4BFB-BB80-F9F2118DECB8"
},
{
"criteria": "cpe:2.3:o:tp-link:nc200_firmware:2.1.9:200225:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "91F2DC6B-5C4F-49DE-8464-78F750A09135"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:nc200:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1856BF12-5B8B-460C-951D-B48DAEFE93F8"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:nc210_firmware:1.0.3:160229:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ACC9C2F6-C933-4EAC-AF64-743063F6CF54"
},
{
"criteria": "cpe:2.3:o:tp-link:nc210_firmware:1.0.4:160412:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D2CA6ACA-92A7-4F9C-9897-8841FE8514E2"
},
{
"criteria": "cpe:2.3:o:tp-link:nc210_firmware:1.0.9:200304:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "12008577-3A10-4C23-A237-AC628D10D8E6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:nc210:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "32E1DC59-F58C-4FB4-A3C0-9A4F8290F8E8"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:nc220_firmware:1.2.0:170516:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "456A7C77-6DDF-40E0-A972-669EDFB5D82F"
},
{
"criteria": "cpe:2.3:o:tp-link:nc220_firmware:1.3.0:180105:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5C11C3AF-540C-4DAF-BF69-96C394D4B43F"
},
{
"criteria": "cpe:2.3:o:tp-link:nc220_firmware:1.3.0:200304:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A47A572A-5DE5-46B2-A942-698286872029"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:nc220:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "09A89384-FA35-492D-B25D-434A049D3A13"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:nc230_firmware:1.0.3:160108:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC051CDE-5054-4925-8D14-B286D01E46B9"
},
{
"criteria": "cpe:2.3:o:tp-link:nc230_firmware:1.2.1:170515:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CA09DB0A-47A0-44D9-AABD-2C335B502B0F"
},
{
"criteria": "cpe:2.3:o:tp-link:nc230_firmware:1.3.0:200304:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BC2CCFDD-290A-46FA-9DC2-8CBAE96258DF"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:nc230:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "3EDB6A57-0D56-43D2-8D36-EC841D9A7FED"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:nc250_firmware:1.0.8:160108:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "488217FC-C02C-4AA3-AD0E-26679E5912FF"
},
{
"criteria": "cpe:2.3:o:tp-link:nc250_firmware:1.0.10:160321:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D2E08C60-2422-4135-B02F-B605386DC314"
},
{
"criteria": "cpe:2.3:o:tp-link:nc250_firmware:1.2.1:170515:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6EB1C532-D019-4EB8-93A0-15FE8DFC07B1"
},
{
"criteria": "cpe:2.3:o:tp-link:nc250_firmware:1.3.0:200304:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4BC014D7-461C-4B63-B79F-B41C55508027"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:nc250:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "3C6A3B4E-F357-4E9F-A799-E58E0D593F19"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:nc260_firmware:1.0.5:160804:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B4227D23-DF7F-484C-8508-341ED2744B52"
},
{
"criteria": "cpe:2.3:o:tp-link:nc260_firmware:1.0.6:161114:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2E7D5E76-892D-46B1-BD46-BD34E0CDFC22"
},
{
"criteria": "cpe:2.3:o:tp-link:nc260_firmware:1.4.1:180720:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C23AB02F-00DA-4844-96EE-6E3976BB5065"
},
{
"criteria": "cpe:2.3:o:tp-link:nc260_firmware:1.5.0:181123:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3F23255A-C021-4B25-86A8-029007EF4D73"
},
{
"criteria": "cpe:2.3:o:tp-link:nc260_firmware:1.5.2:200304:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "54C3D856-5E56-4539-8437-495DCA5CB59E"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:nc260:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0F82284F-1244-45BC-9F38-956219905C97"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:nc450_firmware:1.0.15:160920:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B98EA7FE-B277-44F1-99CD-393FB13D4CC4"
},
{
"criteria": "cpe:2.3:o:tp-link:nc450_firmware:1.1.2:161013:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "72C02D43-51C5-480B-8957-99C9202E87DC"
},
{
"criteria": "cpe:2.3:o:tp-link:nc450_firmware:1.3.4:171130:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B1755D43-FD92-4DAE-B438-711A665C5790"
},
{
"criteria": "cpe:2.3:o:tp-link:nc450_firmware:1.5.3:200304:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "59F5150F-6D80-4B94-9EA6-A20EF1AC7060"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:nc450:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "71C122A0-FEC3-4482-A55D-09FA03A47F56"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}