CVE-2023-53770

HIGH

MiniDVBLinux 5.4 - Info Disclosure

Title source: llm

Description

MiniDVBLinux 5.4 contains an unauthenticated configuration download vulnerability that allows remote attackers to access sensitive system configuration files through a direct object reference. Attackers can exploit the backup download endpoint by sending a GET request with 'action=getconfig' to retrieve a complete system configuration archive containing sensitive credentials.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textremotehardware
https://www.exploit-db.com/exploits/51091

Scores

CVSS v3 7.5
EPSS 0.0039
EPSS Percentile 59.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-260
Status published
Products (2)
minidvblinux/minidvblinux < 5.4
MiniDVBLinux/MiniDVBLinux(TM) Distribution (MLD) <=5.4
Published Dec 09, 2025
Tracked Since Feb 18, 2026