PT-2023-18846 · Trendnet · Trendnet Tv-Ip651Wi Network Camera

Publicado

2023-02-02

·

Atualizado

2025-03-26

·

CVE-2023-23120

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions TRENDnet TV-IP651WI Network Camera versions v1.07.01 and earlier
Description The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes the TRENDnet TV-IP651WI Network Camera vulnerable to firmware modification attacks. An attacker can conduct a man-in-the-middle (MITM) attack to modify the new firmware image and bypass the checksum verification.
Recommendations For versions v1.07.01 and earlier, consider implementing additional integrity checks, such as digital signatures, to prevent firmware modification attacks. As a temporary workaround, restrict access to the firmware update process to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-23120

Produtos afetados

Trendnet Tv-Ip651Wi Network Camera