MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands as root through the 'command' GET parameter. Attackers can exploit the /tpl/commands.sh endpoint by sending malicious command values to gain root-level system access.
The command injection vulnerability occurs in the /tpl/commands.sh endpoint, which processes a GET parameter named 'command'. An attacker can send a specially crafted HTTP request containing malicious values of this parameter, which are then executed by the operating system without any validation or authentication. Since commands are executed in the root account context, the attacker gains immediate, full access to the system.
An attacker without any authentication can execute arbitrary system commands with root privileges, which in practice means full takeover of the device, ability to read and modify all data, and further actions on the network.
Patches available from the vendor should be applied according to the references. As an immediate protective measure, it is recommended to isolate MiniDVBLinux devices from public network access and restrict access to the management interface only to trusted hosts using a firewall.
MiniDVBLinux version 5.4
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMinidvblinux
APPMinidvblinux5.4
Related vulnerabilities
MiniDVBLinux 5.4 — Authentication Bypass umożliwiający zmianę hasła root
MiniDVBLinux ≤5.4 — OS command injection z pominięciem uwierzytelnienia
MiniDVBLinux 5.4 contains an unauthenticated configuration download vulnerability that allows remote attackers...
MiniDVBLinux 5.4 contains an arbitrary file disclosure vulnerability that allows attackers to read sensitive s...
MiniDVBLinux 5.4 contains an unauthenticated vulnerability in the tv_action.sh script that allows remote attac...