CVE-2023-49237: TRENDnet Tv-IP1314PI Firmware

Critical severity, CVSS 9.8. EPSS: 18.6% chance of exploitation in the next 30 days.

An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system function is used by davinci to unpack language packs without strict filtering of URL strings.

Affected products

  • TRENDnet Tv-IP1314PI Firmware: version 5.5.3 only

Published 2024-01-09. Last modified 2026-06-17.