SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP TP-LINK Cloud Cameras NCXXX Bonjour command injection attempt
This rule is looking precisely for a command injection within the 'sysname' parameter of the setsysname.fcgi page.
This rule is triggered by an attempt to exploit CVE-2020-12109 via a command injection through HTTP.
Public information/Proof of Concept available
No known false positives
Cisco Talos Intelligence Group
No rule groups