PT-2024-13706 · Trendnet · Trendnet Tv-Ip1314Pi

CVE-2023-49237

·

Published

2024-01-09

·

Updated

2025-06-20

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TRENDnet TV-IP1314PI version 5.5.3 200714
Description An issue was discovered where command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.
Recommendations For TRENDnet TV-IP1314PI version 5.5.3 200714, consider disabling the davinci function until a patch is available to prevent command injection. Restrict access to the system function to minimize the risk of exploitation. Avoid using unfiltered URL strings in the language pack unpacking process until the issue is resolved.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-49237

Affected Products

Trendnet Tv-Ip1314Pi