peter bassill · operator
$ cve CVE-2023-49237 JSON

CVE-2023-49237

9.8
CRITICAL · CVSS 3.1 · EPSS 18.6% (pctl 97)

Patch early

EPSS 18.6% — above the 10% action threshold.

Description

An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS18.6% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploitnone known
Published2024-01-09
Last modified2026-06-17

Affected (2)

VendorProduct
trendnettv-ip1314pi
trendnettv-ip1314pi firmware

References

→ the Explorer  ·  watch your stack  ·  NVD