CVE-2023-49237

CRITICAL

TRENDnet TV-IP1314PI <5.5.3 - Command Injection

Title source: llm
STIX 2.1

Description

An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.

Scores

CVSS v3 9.8
EPSS 0.6980
EPSS Percentile 98.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-77
Status published
Products (1)
trendnet/tv-ip1314pi_firmware 5.5.3 200714
Published Jan 09, 2024
Tracked Since Feb 18, 2026