Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-49237


An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.


Published

2024-01-09T09:15:42.350

Last Modified

2025-06-20T16:15:25.543

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-77
  • Type: Secondary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System trendnet tv-ip1314pi_firmware 5.5.3 Yes
Hardware trendnet tv-ip1314pi - No

References