VYPR

TV-IP1314PI

by Trendnet

CVEs (3)

  • CVE-2023-49237CriJan 9, 2024
    risk 0.65cvss 9.8epss 0.19

    An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.

  • CVE-2023-49236CriJan 9, 2024
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices, leading to arbitrary command execution. This occurs because of lack of length validation during an sscanf of a user-entered scale field in the RTSP playback function of davinci.

  • CVE-2023-49235CriJan 9, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in libremote_dbg.so on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Filtering of debug information is mishandled during use of popen. Consequently, an attacker can bypass validation and execute a shell command.