CVE-2023-49237

An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:trendnet:tv-ip1314pi_firmware:5.5.3:200714:*:*:*:*:*:*
cpe:2.3:h:trendnet:tv-ip1314pi:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:33

Type Values Removed Values Added
References () https://drive.google.com/file/d/1lTloBkH_7zAz1ZbFVSZnfpoPd81aPaHx/view?usp=sharing - Exploit, Vendor Advisory () https://drive.google.com/file/d/1lTloBkH_7zAz1ZbFVSZnfpoPd81aPaHx/view?usp=sharing - Exploit, Vendor Advisory
References () https://github.com/pcsle37/TRENDnet/blob/main/TRENDnet_vul.pdf - Exploit, Third Party Advisory () https://github.com/pcsle37/TRENDnet/blob/main/TRENDnet_vul.pdf - Exploit, Third Party Advisory

16 Jan 2024, 14:51

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Trendnet tv-ip1314pi Firmware
Trendnet
Trendnet tv-ip1314pi
References () https://drive.google.com/file/d/1lTloBkH_7zAz1ZbFVSZnfpoPd81aPaHx/view?usp=sharing - () https://drive.google.com/file/d/1lTloBkH_7zAz1ZbFVSZnfpoPd81aPaHx/view?usp=sharing - Exploit, Vendor Advisory
References () https://github.com/pcsle37/TRENDnet/blob/main/TRENDnet_vul.pdf - () https://github.com/pcsle37/TRENDnet/blob/main/TRENDnet_vul.pdf - Exploit, Third Party Advisory
CPE cpe:2.3:o:trendnet:tv-ip1314pi_firmware:5.5.3:200714:*:*:*:*:*:*
cpe:2.3:h:trendnet:tv-ip1314pi:-:*:*:*:*:*:*:*
CWE CWE-77

09 Jan 2024, 14:01

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en los dispositivos TRENDnet TV-IP1314PI 5.5.3 200714. La inyección de comandos puede ocurrir porque davinci utiliza la función del sistema para descomprimir paquetes de idiomas sin un filtrado estricto de las cadenas de URL.

09 Jan 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-09 09:15

Updated : 2024-11-21 08:33


NVD link : CVE-2023-49237

Mitre link : CVE-2023-49237

CVE.ORG link : CVE-2023-49237


JSON object : View

Products Affected

trendnet

  • tv-ip1314pi_firmware
  • tv-ip1314pi
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')