PT-2023-18846 · Trendnet · Trendnet Tv-Ip651Wi Network Camera
Publicado
2023-02-02
·
Atualizado
2025-03-26
·
CVE-2023-23120
CVSS v3.1
5.9
Média
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
TRENDnet TV-IP651WI Network Camera versions v1.07.01 and earlier
Description
The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes the TRENDnet TV-IP651WI Network Camera vulnerable to firmware modification attacks. An attacker can conduct a man-in-the-middle (MITM) attack to modify the new firmware image and bypass the checksum verification.
Recommendations
For versions v1.07.01 and earlier, consider implementing additional integrity checks, such as digital signatures, to prevent firmware modification attacks. As a temporary workaround, restrict access to the firmware update process to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Trendnet Tv-Ip651Wi Network Camera