CVE-2023-53771

CRITICAL

MiniDVBLinux 5.4 - Unauthenticated Root Password Change via System Setup Endpoint

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-53771. PoCs published by LiquidWorm.

AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in MiniDVBLinux 5.4, allowing unauthenticated remote attackers to change the root password via a crafted POST request. The vulnerability arises from disabled authentication checks in the system setup interface.

Description

MiniDVBLinux 5.4 contains an authentication bypass vulnerability that allows remote attackers to change the root password without authentication. Attackers can send crafted POST requests to the system setup endpoint with modified SYSTEM_PASSWORD parameters to reset root credentials.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textremotehardware
https://www.exploit-db.com/exploits/51094

This exploit demonstrates an authentication bypass vulnerability in MiniDVBLinux 5.4, allowing unauthenticated remote attackers to change the root password via a crafted POST request. The vulnerability arises from disabled authentication checks in the system setup interface.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: MiniDVBLinux <=5.4
No auth needed
Prerequisites: Network access to the target system · Web interface exposed on port 8008
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Third Party Advisory, VDB Entry exploit
https://www.exploit-db.com/exploits/51094
Exploit, Third Party Advisory third-party-advisory
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5715.php
Product product
https://www.minidvblinux.de

Scores

CVSS v3 9.8
EPSS 0.0087
EPSS Percentile 53.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (2)
minidvblinux/minidvblinux < 5.4
MiniDVBLinux/MiniDVBLinux Change Root Password PoC <=5.4
Published Dec 09, 2025
Tracked Since Feb 18, 2026