Описание
An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execute arbitrary commands as the root user, potentially compromising the entire device.
An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execute arbitrary commands as the root user, potentially compromising the entire device.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2025-25038
- https://cxsecurity.com/issue/WLB-2022100039
- https://packetstormsecurity.com/files/168744
- https://vulncheck.com/advisories/minidvblinux-command-injection
- https://www.exploit-db.com/exploits/51096
- https://www.fortiguard.com/encyclopedia/ips/52454
- https://www.minidvblinux.de
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5717.php
EPSS
9.3 Critical
CVSS4
9.8 Critical
CVSS3
CVE ID
Дефекты
Связанные уязвимости
An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execute arbitrary commands as the root user, potentially compromising the entire device. Exploitation evidence was observed by the Shadowserver Foundation on 2024-04-10 UTC.
EPSS
9.3 Critical
CVSS4
9.8 Critical
CVSS3