CRITICAL🇵🇱 Wersja polska

CVE-2022-50691

CVSS 9.3v4.0pub. 2025-12-30upd. 2026-01-12

MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands as root through the 'command' GET parameter. Attackers can exploit the /tpl/commands.sh endpoint by sending malicious command values to gain root-level system access.

🤖 AI Analysis
How it works

The command injection vulnerability occurs in the /tpl/commands.sh endpoint, which processes a GET parameter named 'command'. An attacker can send a specially crafted HTTP request containing malicious values of this parameter, which are then executed by the operating system without any validation or authentication. Since commands are executed in the root account context, the attacker gains immediate, full access to the system.

Impact

An attacker without any authentication can execute arbitrary system commands with root privileges, which in practice means full takeover of the device, ability to read and modify all data, and further actions on the network.

Mitigation & patch

Patches available from the vendor should be applied according to the references. As an immediate protective measure, it is recommended to isolate MiniDVBLinux devices from public network access and restrict access to the management interface only to trusted hosts using a firewall.

Who is affected

MiniDVBLinux version 5.4

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Minidvblinux

    APP
    Minidvblinux
    5.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassCommand Injection
CWE
References

Related vulnerabilities

CVE-2023-53771CRITICAL9.3PL ✓same product

MiniDVBLinux 5.4 — Authentication Bypass umożliwiający zmianę hasła root

CVE-2025-25038CRITICAL9.3PL ✓same product

MiniDVBLinux ≤5.4 — OS command injection z pominięciem uwierzytelnienia

CVE-2023-53770HIGH8.7same product

MiniDVBLinux 5.4 contains an unauthenticated configuration download vulnerability that allows remote attackers...

CVE-2023-53772HIGH8.7same product

MiniDVBLinux 5.4 contains an arbitrary file disclosure vulnerability that allows attackers to read sensitive s...

CVE-2023-53773HIGH8.7same product

MiniDVBLinux 5.4 contains an unauthenticated vulnerability in the tv_action.sh script that allows remote attac...