CVE-2025-25038
MiniDVBLinux Root Command Injection
Severity
Critical 9.3
CVSS 4.0
Exploited
Not listed
EPSS
0.053
91.8th percentile
Discovered by
Unknown
Published by the vendor
Published
Jun 20, 2025
Assigned by vulncheck
Description
An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execute arbitrary commands as the root user, potentially compromising the entire device. Exploitation evidence was observed by the Shadowserver Foundation on 2024-04-10 UTC.
Weakness: CWE-78
Affected products
| Vendor | Product | Category | Matched by |
|---|
No product mapping yet — this CVE is pending taxonomy review.
Vendor-reported affected versions (1)
- MiniDVBLinux · MiniDVBLinux
Credit
Gjoko Krstic
References
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5717.php
- https://www.exploit-db.com/exploits/51096
- https://www.fortiguard.com/encyclopedia/ips/52454
- https://cxsecurity.com/issue/WLB-2022100039
- https://packetstormsecurity.com/files/168744/
- https://www.minidvblinux.de
- https://vulncheck.com/advisories/minidvblinux-command-injection