Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r3xp-pwxv-p43m

Опубликовано: 20 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execute arbitrary commands as the root user, potentially compromising the entire device.

An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execute arbitrary commands as the root user, potentially compromising the entire device.

EPSS

Процентиль: 95%
0.17592
Средний

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-78

Связанные уязвимости

CVSS3: 9.8
nvd
8 месяцев назад

An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execute arbitrary commands as the root user, potentially compromising the entire device. Exploitation evidence was observed by the Shadowserver Foundation on 2024-04-10 UTC.

EPSS

Процентиль: 95%
0.17592
Средний

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-78