An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2024-01-09T00:00:00

Updated: 2024-01-09T08:48:21.677572

Reserved: 2023-11-24T00:00:00


Link: CVE-2023-49237

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2024-01-09T09:15:42.350

Modified: 2024-01-16T14:51:27.687


Link: CVE-2023-49237

JSON object: View

cve-icon Redhat Information

No data.

CWE