PT-2023-18846 · Trendnet · Trendnet Tv-Ip651Wi Network Camera
Published
2023-02-02
·
Updated
2025-03-26
·
CVE-2023-23120
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
TRENDnet TV-IP651WI Network Camera versions v1.07.01 and earlier
Description
The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update makes the TRENDnet TV-IP651WI Network Camera vulnerable to firmware modification attacks. An attacker can conduct a man-in-the-middle (MITM) attack to modify the new firmware image and bypass the checksum verification.
Recommendations
For versions v1.07.01 and earlier, consider implementing additional integrity checks, such as digital signatures, to prevent firmware modification attacks. As a temporary workaround, restrict access to the firmware update process to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trendnet Tv-Ip651Wi Network Camera