CVE-2023-49235: OS Command Injection
An issue was discovered in libremotedbg.so on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Filtering of debug information is mishandled during use of popen. Consequently, an attacker can bypass validation and execute a shell command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49235?
CVE-2023-49235 has been classified as a high severity vulnerability due to its potential to allow arbitrary command execution.
How do I fix CVE-2023-49235?
To fix CVE-2023-49235, update the TRENDnet TV-IP1314PI firmware to the latest version that addresses this vulnerability.
What devices are affected by CVE-2023-49235?
CVE-2023-49235 specifically affects TRENDnet TV-IP1314PI devices running firmware version 5.5.3 200714.
What type of attack can be executed by exploiting CVE-2023-49235?
An attacker can exploit CVE-2023-49235 to bypass validation and execute arbitrary shell commands on the affected devices.
Is CVE-2023-49235 related to remote debugging features?
Yes, CVE-2023-49235 is related to a mishandling of debug information during the use of popen in libremote_dbg.so.