CVE-2019-11417: TRENDnet Tv-IP110WN Firmware

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

system.cgi on TRENDnet TV-IP110WN cameras has a buffer overflow caused by an inadequate source-length check before a strcpy operation in the respondAsp function. Attackers can exploit the vulnerability by using the languse parameter with a long string. This affects 1.2.2 build 28, 64, 65, and 68.

Affected products

  • TRENDnet Tv-IP110WN Firmware: version 1.2.2.28 only; version 1.2.2.64 only; version 1.2.2.65 only; version 1.2.2.68 only

Published 2019-04-22. Last modified 2026-06-17.