CVE Feed

    Dashboard / CVE / CVE-2023-49237

    CVE-2023-49237

    An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.

    Published:Jan 9, 2024
    Last Modified:Jun 20, 2025
    EPS:Jan 9, 2024
    EPSS Score:0.03296
    CVSS Score:9.8

    Affected Products

    Vendor
    Trendnet
    Product
    Tv-ip1314pi
    Vendor
    Trendnet
    Product
    Tv-ip1314pi Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High