PT-2018-14888 · Trendnet · Trendnet Tv-Ip110Wn+1

Hamed Okhravi

+3

·

Published

2018-12-20

·

Updated

2019-01-14

·

CVE-2018-19241

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions TRENDnet TV-IP110WN versions 1.2.2 build 64 through 1.2.2 build 68 TRENDnet TV-IP110WN version 1.2.2.65 TRENDnet TV-IP121WN version 1.2.2 build 28
Description The issue allows attackers to hijack the control flow to any attacker-specified location by crafting a POST request payload without authentication. This is due to a buffer overflow in the video.cgi component.
Recommendations For TRENDnet TV-IP110WN versions 1.2.2 build 64 through 1.2.2 build 68, consider restricting access to the video.cgi component until a patch is available. For TRENDnet TV-IP110WN version 1.2.2.65, consider restricting access to the video.cgi component until a patch is available. For TRENDnet TV-IP121WN version 1.2.2 build 28, consider restricting access to the video.cgi component until a patch is available. As a temporary workaround, avoid using the video.cgi component in the affected devices until the issue is resolved.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-19241

Affected Products

Trendnet Tv-Ip110Wn
Trendnet Tv-Ip121Wn