Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-25038

Опубликовано: 20 июн. 2025
Источник: nvd
CVSS3: 9.8
EPSS Средний

Описание

An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execute arbitrary commands as the root user, potentially compromising the entire device. Exploitation evidence was observed by the Shadowserver Foundation on 2024-04-10 UTC.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:minidvblinux:minidvblinux:*:*:*:*:*:*:*:*
Версия до 5.4 (включая)

EPSS

Процентиль: 95%
0.17592
Средний

9.8 Critical

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 9.8
github
8 месяцев назад

An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execute arbitrary commands as the root user, potentially compromising the entire device.

EPSS

Процентиль: 95%
0.17592
Средний

9.8 Critical

CVSS3

Дефекты

CWE-78