← Back to browse · API

CVE-2023-49237

Severity
CRITICAL
CVSS
9.8
EPSS
0.18596
Risk score
45.71
CISA KEV
No
PoC
No
Published
2024-01-09
Modified
2025-06-20
First seen
2026-08-07
Aliases
EUVD-2023-53240, GHSA-CFR6-FJFX-M5R2
Products
n/a:n/a n/a
Sources
euvd EUVD-2023-53240

Description

An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.

References