CVE-2013-2579

CRITICAL ⚠ Exploit

TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 have an empty password for the hardcoded "qmik" account, which all...

Affects 5 products across 1 vendor.

BCS8.9
CVSS 2.010.0
EPSS3.9%
Percentile89th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-255: CWE-255
◆ SAGE Intelligence — CITED Relevance Research Team

TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 have a critical vulnerability due to an empty password for the hardcoded 'qmik' account, allowing remote attackers to gain administrative access via TELNET.

BSID: BS-2013-GLOBAL-157383-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2013-2579?
TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 have a critical vulnerability due to an empty password for the hardcoded 'qmik' account, allowing remote attackers to gain administrative access via TELNET.
What is the CVSS score for CVE-2013-2579?
CVE-2013-2579 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 3.9%.
Is CVE-2013-2579 actively exploited?
Public exploit available for CVE-2013-2579. Exploitation risk elevated.
How do I remediate CVE-2013-2579?
Priority: IMMEDIATE.
What systems are affected by CVE-2013-2579?
CVE-2013-2579 affects: Tp-Link, Tp-Link, Tp-Link, Tp-Link, Tp-Link.
Vulnerability Details
CVE IDCVE-2013-2579
BSIDBS-2013-GLOBAL-157383-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2013-10-11
Last Modified2026-04-29
ICS Relevance85%
Weakness (CWE)
SourceNVD
Official Description

TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 have an empty password for the hardcoded "qmik" account, which allows remote attackers to obtain administrative access via a TELNET session.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is exploited by connecting to the camera's TELNET service using the hardcoded username 'qmik' and an empty password. This allows attackers to obtain administrative privileges, potentially leading to unauthorized access, configuration changes, or even full control of the device.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Tp-Link Tl-Sc3130
Tp-Link Tl-Sc3130G
Tp-Link Tl-Sc3171
Tp-Link Tl-Sc3171G
Tp-Link Lm Firmware
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 4681 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
Related CVEs affecting Tp-Link
CVE-2013-2578 10.0 cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC317... CVE-2024-25139 10.0 In TP-Link Omada er605 1.0.1 through (v2.6) 2.2.3, a cloud-brd binary is susc... CVE-2023-36355 9.9 TP-Link TL-WR940N V4 was discovered to contain a buffer overflow via the ipSt... CVE-2017-8220 9.9 TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 R... CVE-2023-31710 9.8 TP-Link Archer AX21(US)_V3_1.1.4 Build 20230219 and AX21(US)_V3.6_1.1.4 Build...
View all Tp-Link CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →