CVE-2020-12111: TP-Link NC260 Firmware
High severity, CVSS 8.8. EPSS: 7.9% chance of exploitation in the next 30 days.
Certain TP-Link devices allow Command Injection. This affects NC260 1.5.2 build 200304 and NC450 1.5.3 build 200304.
Affected products
- TP-Link NC260 Firmware: version 1.0.5 only; version 1.0.6 only; version 1.4.1 only; version 1.5.0 only; version 1.5.2 only
- TP-Link NC450 Firmware: version 1.0.15 only; version 1.1.2 only; version 1.3.4 only; version 1.5.3 only
Published 2020-05-04. Last modified 2026-06-17.