PT-2024-13706 · Trendnet · Trendnet Tv-Ip1314Pi

Published

2024-01-09

·

Updated

2025-06-20

·

CVE-2023-49237

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TRENDnet TV-IP1314PI version 5.5.3 200714
Description An issue was discovered where command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.
Recommendations For TRENDnet TV-IP1314PI version 5.5.3 200714, consider disabling the davinci function until a patch is available to prevent command injection. Restrict access to the system function to minimize the risk of exploitation. Avoid using unfiltered URL strings in the language pack unpacking process until the issue is resolved.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-49237

Affected Products

Trendnet Tv-Ip1314Pi