CVE-2025-25038

An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execute arbitrary commands as the root user, potentially compromising the entire device. Exploitation evidence was observed by the Shadowserver Foundation on 2024-04-10 UTC.
Configurations

Configuration 1 (hide)

cpe:2.3:a:minidvblinux:minidvblinux:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-06-20 19:15

Updated : 2025-12-22 17:46


NVD link : CVE-2025-25038

Mitre link : CVE-2025-25038

CVE.ORG link : CVE-2025-25038


JSON object : View

Products Affected

minidvblinux

  • minidvblinux
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')