CRITICAL🇵🇱 Wersja polska

CVE-2025-25038

CVSS 9.3v4.0pub. 2025-06-20upd. 2025-12-22

An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execute arbitrary commands as the root user, potentially compromising the entire device. Exploitation evidence was observed by the Shadowserver Foundation on 2024-04-10 UTC.

🤖 AI Analysis
How it works

The web interface of the MiniDVBLinux system does not perform proper validation or sanitization of data supplied by users before passing it to operating system commands. An attacker can inject malicious commands through a specially crafted HTTP request, which will be executed by the system without any authentication mechanism. The vulnerability is classified as CWE-78 (OS Command Injection) and requires no privileges or user interaction. The Shadowserver Foundation has documented evidence of active exploitation of this vulnerability in production environments.

Impact

An attacker gains the ability to execute arbitrary commands with root privileges, leading to complete takeover of the device — including reading and modifying data, installing malware, and conducting further lateral movement across the network.

Mitigation & patch

Patches available from the vendor should be applied according to the references. Due to the lack of authentication mechanism as a protective layer, vulnerable devices should not be directly accessible from the Internet — they should be isolated behind a firewall or segmented on the network until updates are deployed.

Who is affected

MiniDVBLinux version 5.4 and earlier

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Minidvblinux

    APP
    Minidvblinux
    ≤ 5.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassCommand Injection
CWE
References

Related vulnerabilities

CVE-2022-50691CRITICAL9.3PL ✓same product

MiniDVBLinux 5.4 — zdalny RCE jako root przez command injection

CVE-2023-53771CRITICAL9.3PL ✓same product

MiniDVBLinux 5.4 — Authentication Bypass umożliwiający zmianę hasła root

CVE-2023-53770HIGH8.7same product

MiniDVBLinux 5.4 contains an unauthenticated configuration download vulnerability that allows remote attackers...

CVE-2023-53772HIGH8.7same product

MiniDVBLinux 5.4 contains an arbitrary file disclosure vulnerability that allows attackers to read sensitive s...

CVE-2023-53773HIGH8.7same product

MiniDVBLinux 5.4 contains an unauthenticated vulnerability in the tv_action.sh script that allows remote attac...