CVE-2023-49237: Command Injection
An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-49237?
CVE-2023-49237 is classified as a high-severity vulnerability due to its potential for command injection.
How do I fix CVE-2023-49237?
To fix CVE-2023-49237, update the firmware of TRENDnet TV-IP1314PI to a version that addresses this issue.
What devices are affected by CVE-2023-49237?
CVE-2023-49237 specifically affects the Trendnet TV-IP1314PI devices running firmware version 5.5.3-200714.
What type of vulnerability is CVE-2023-49237?
CVE-2023-49237 is a command injection vulnerability due to improper filtering of URL strings during the unpacking of language packs.
Can CVE-2023-49237 be exploited remotely?
Yes, CVE-2023-49237 can potentially be exploited remotely if the device is accessible from the internet.