cbcvebase.

Minidvblinux vulnerabilities

7 known vulnerabilities affecting minidvblinux/minidvblinux.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL4HIGH2MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2025-25038P1CRITICALCVSS 9.8Exploited≤ 5.42025-06-20
CVE-2025-25038 [CRITICAL] CWE-78 CVE-2025-25038: An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s w An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execute arbitrary commands as the root user, potentially
nvd
CVE-2022-50691P2CRITICALCVSS 9.8v5.4≥ Unknown, ≤ 5.42025-12-30
CVE-2022-50691 [CRITICAL] CWE-78 CVE-2022-50691: MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attac MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands as root through the 'command' GET parameter. Attackers can exploit the /tpl/commands.sh endpoint by sending malicious command values to gain root-level system access.
nvd
CVE-2023-53771P2CRITICALCVSS 9.8≤ 5.42025-12-09
CVE-2023-53771 [CRITICAL] CWE-306 CVE-2023-53771: MiniDVBLinux 5.4 contains an authentication bypass vulnerability that allows remote attackers to cha MiniDVBLinux 5.4 contains an authentication bypass vulnerability that allows remote attackers to change the root password without authentication. Attackers can send crafted POST requests to the system setup endpoint with modified SYSTEM_PASSWORD parameters to reset root credentials.
nvd
CVE-2023-53774P2CRITICALCVSS 9.8≤ 5.42025-12-09
CVE-2023-53774 [CRITICAL] CWE-306 CVE-2023-53774: MiniDVBLinux 5.4 contains a remote code execution vulnerability in the SVDRP protocol that allows re MiniDVBLinux 5.4 contains a remote code execution vulnerability in the SVDRP protocol that allows remote attackers to send commands to manipulate TV systems. Attackers can send crafted SVDRP commands through the svdrpsend.sh script to execute messages and potentially control the video disk recorder remotely.
nvd
CVE-2023-53770P3HIGHCVSS 7.5≤ 5.42025-12-09
CVE-2023-53770 [HIGH] CWE-260 CVE-2023-53770: MiniDVBLinux 5.4 contains an unauthenticated configuration download vulnerability that allows remote MiniDVBLinux 5.4 contains an unauthenticated configuration download vulnerability that allows remote attackers to access sensitive system configuration files through a direct object reference. Attackers can exploit the backup download endpoint by sending a GET request with 'action=getconfig' to retrieve a complete system configuration archive containi
nvd
CVE-2023-53772P3HIGHCVSS 7.5≤ 5.4v<=5.42025-12-09
CVE-2023-53772 [HIGH] CWE-22 CVE-2023-53772: MiniDVBLinux 5.4 contains an arbitrary file disclosure vulnerability that allows attackers to read s MiniDVBLinux 5.4 contains an arbitrary file disclosure vulnerability that allows attackers to read sensitive system files through the 'file' GET parameter. Attackers can exploit the about page by supplying file paths to disclose arbitrary file contents on the affected device.
nvd
CVE-2023-53773P3MEDIUMCVSS 5.3≤ 5.4v<=5.42025-12-09
CVE-2023-53773 [MEDIUM] CWE-306 CVE-2023-53773: MiniDVBLinux 5.4 contains an unauthenticated vulnerability in the tv_action.sh script that allows re MiniDVBLinux 5.4 contains an unauthenticated vulnerability in the tv_action.sh script that allows remote attackers to generate live stream snapshots through the Simple VDR Protocol. Attackers can request /tpl/tv_action.sh to create and retrieve a live TV screenshot stored in /var/www/images/tv.jpg without authentication.
nvd
Minidvblinux vulnerabilities | cvebase