PT-2023-18846 · Trendnet · Trendnet Tv-Ip651Wi Network Camera

Published

2023-02-02

·

Updated

2025-03-26

·

CVE-2023-23120

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions TRENDnet TV-IP651WI Network Camera versions v1.07.01 and earlier
Description The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes the TRENDnet TV-IP651WI Network Camera vulnerable to firmware modification attacks. An attacker can conduct a man-in-the-middle (MITM) attack to modify the new firmware image and bypass the checksum verification.
Recommendations For versions v1.07.01 and earlier, consider implementing additional integrity checks, such as digital signatures, to prevent firmware modification attacks. As a temporary workaround, restrict access to the firmware update process to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-23120

Affected Products

Trendnet Tv-Ip651Wi Network Camera