CRITICAL🇵🇱 Wersja polska

CVE-2023-53771

CVSS 9.3v4.0pub. 2025-12-09upd. 2025-12-19

MiniDVBLinux 5.4 contains an authentication bypass vulnerability that allows remote attackers to change the root password without authentication. Attackers can send crafted POST requests to the system setup endpoint with modified SYSTEM_PASSWORD parameters to reset root credentials.

🤖 AI Analysis
How it works

An attacker sends a crafted HTTP POST request to the system configuration endpoint, passing modified SYSTEM_PASSWORD parameters. The vulnerability mechanism results from the lack of user identity verification (CWE-306 — Missing Authentication for Critical Function) before executing the password change operation. As a result, the system accepts and processes the request without checking whether the sender is authorized to make this change.

Impact

An attacker can reset the root account password to any arbitrary value, thereby obtaining full administrative privileges on the system. This results in complete loss of confidentiality and integrity of data on the device.

Mitigation & patch

Apply patches available from the manufacturer according to the references provided. As a temporary measure, it is recommended to restrict network access to the device's administrative interface using a firewall or network segmentation to prevent unauthorized hosts from sending requests to the system configuration endpoint.

Who is affected

MiniDVBLinux version 5.4

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Minidvblinux

    APP
    Minidvblinux
    ≤ 5.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2022-50691CRITICAL9.3PL ✓same product

MiniDVBLinux 5.4 — zdalny RCE jako root przez command injection

CVE-2025-25038CRITICAL9.3PL ✓same product

MiniDVBLinux ≤5.4 — OS command injection z pominięciem uwierzytelnienia

CVE-2023-53770HIGH8.7same product

MiniDVBLinux 5.4 contains an unauthenticated configuration download vulnerability that allows remote attackers...

CVE-2023-53772HIGH8.7same product

MiniDVBLinux 5.4 contains an arbitrary file disclosure vulnerability that allows attackers to read sensitive s...

CVE-2023-53773HIGH8.7same product

MiniDVBLinux 5.4 contains an unauthenticated vulnerability in the tv_action.sh script that allows remote attac...