CVE-2025-25038

An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execute arbitrary commands as the root user, potentially compromising the entire device. Exploitation evidence was observed by the Shadowserver Foundation on 2024-04-10 UTC.
Configurations

Configuration 1 (hide)

cpe:2.3:a:minidvblinux:minidvblinux:*:*:*:*:*:*:*:*

History

22 Dec 2025, 17:46

Type Values Removed Values Added
References () https://cxsecurity.com/issue/WLB-2022100039 - () https://cxsecurity.com/issue/WLB-2022100039 - Third Party Advisory
References () https://packetstormsecurity.com/files/168744/ - () https://packetstormsecurity.com/files/168744/ - Third Party Advisory
References () https://vulncheck.com/advisories/minidvblinux-command-injection - () https://vulncheck.com/advisories/minidvblinux-command-injection - Third Party Advisory
References () https://www.exploit-db.com/exploits/51096 - () https://www.exploit-db.com/exploits/51096 - Exploit, Third Party Advisory, VDB Entry
References () https://www.fortiguard.com/encyclopedia/ips/52454 - () https://www.fortiguard.com/encyclopedia/ips/52454 - Third Party Advisory
References () https://www.minidvblinux.de - () https://www.minidvblinux.de - Product
References () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5717.php - () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5717.php - Exploit, Third Party Advisory
CPE cpe:2.3:a:minidvblinux:minidvblinux:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Minidvblinux
Minidvblinux minidvblinux

20 Nov 2025, 17:15

Type Values Removed Values Added
Summary (en) An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execute arbitrary commands as the root user, potentially compromising the entire device. (en) An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execute arbitrary commands as the root user, potentially compromising the entire device. Exploitation evidence was observed by the Shadowserver Foundation on 2024-04-10 UTC.
CWE CWE-20

23 Jun 2025, 20:16

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de inyección de comandos en el sistema operativo MiniDVBLinux versión 5.4 y anteriores. La interfaz de administración web del sistema no depura correctamente la entrada del usuario antes de pasarla a los comandos del sistema operativo. Un atacante remoto no autenticado puede explotar esta vulnerabilidad para ejecutar comandos arbitrarios como usuario root, lo que podría comprometer todo el dispositivo.

20 Jun 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-20 19:15

Updated : 2025-12-22 17:46


NVD link : CVE-2025-25038

Mitre link : CVE-2025-25038

CVE.ORG link : CVE-2025-25038


JSON object : View

Products Affected

minidvblinux

  • minidvblinux
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')