system.cgi on TRENDnet TV-IP110WN cameras has a buffer overflow caused by an inadequate source-length check before a strcpy operation in the respondAsp function. Attackers can exploit the vulnerability by using the languse parameter with a long string. This affects 1.2.2 build 28, 64, 65, and 68.
2019-04-22T11:29:05.517
2024-11-21T04:21:04.480
Modified
CVSSv3.0: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | trendnet | tv-ip110wn_firmware | 1.2.2.28 | Yes |
Operating System | trendnet | tv-ip110wn_firmware | 1.2.2.64 | Yes |
Operating System | trendnet | tv-ip110wn_firmware | 1.2.2.65 | Yes |
Operating System | trendnet | tv-ip110wn_firmware | 1.2.2.68 | Yes |
Hardware | trendnet | tv-ip110wn | - | No |