CVE-2019-11417: Input Validation
system.cgi on TRENDnet TV-IP110WN cameras has a buffer overflow caused by an inadequate source-length check before a strcpy operation in the respondAsp function. Attackers can exploit the vulnerability by using the languse parameter with a long string. This affects 1.2.2 build 28, 64, 65, and 68.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-11417?
CVE-2019-11417 is a high severity vulnerability due to the potential for remote code execution through a buffer overflow.
How do I fix CVE-2019-11417?
To fix CVE-2019-11417, update the TRENDnet TV-IP110WN camera firmware to the latest version provided by TRENDnet.
Which devices are affected by CVE-2019-11417?
CVE-2019-11417 affects TRENDnet TV-IP110WN cameras running firmware versions 1.2.2 build 28, 64, 65, and 68.
What is the cause of CVE-2019-11417?
CVE-2019-11417 is caused by a buffer overflow resulting from an inadequate source-length check before a strcpy operation in the system.cgi file.
Can CVE-2019-11417 be exploited remotely?
Yes, CVE-2019-11417 can be remotely exploited by attackers using a specially crafted languse parameter.