An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execute arbitrary commands as the root user, potentially compromising the entire device. Exploitation evidence was observed by the Shadowserver Foundation on 2024-04-10 UTC.
The web interface of the MiniDVBLinux system does not perform proper validation or sanitization of data supplied by users before passing it to operating system commands. An attacker can inject malicious commands through a specially crafted HTTP request, which will be executed by the system without any authentication mechanism. The vulnerability is classified as CWE-78 (OS Command Injection) and requires no privileges or user interaction. The Shadowserver Foundation has documented evidence of active exploitation of this vulnerability in production environments.
An attacker gains the ability to execute arbitrary commands with root privileges, leading to complete takeover of the device — including reading and modifying data, installing malware, and conducting further lateral movement across the network.
Patches available from the vendor should be applied according to the references. Due to the lack of authentication mechanism as a protective layer, vulnerable devices should not be directly accessible from the Internet — they should be isolated behind a firewall or segmented on the network until updates are deployed.
MiniDVBLinux version 5.4 and earlier
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMinidvblinux
APPMinidvblinux≤ 5.4
Related vulnerabilities
MiniDVBLinux 5.4 — zdalny RCE jako root przez command injection
MiniDVBLinux 5.4 — Authentication Bypass umożliwiający zmianę hasła root
MiniDVBLinux 5.4 contains an unauthenticated configuration download vulnerability that allows remote attackers...
MiniDVBLinux 5.4 contains an arbitrary file disclosure vulnerability that allows attackers to read sensitive s...
MiniDVBLinux 5.4 contains an unauthenticated vulnerability in the tv_action.sh script that allows remote attac...