CVE-2025-25038
CRITICAL EXPLOITEDMiniDVBLinux <5.4 - Command Injection
Title source: llmDescription
An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execute arbitrary commands as the root user, potentially compromising the entire device. Exploitation evidence was observed by the Shadowserver Foundation on 2024-04-10 UTC.
Exploits (1)
exploitdb
WORKING POC
by LiquidWorm · pythonremotehardware
https://www.exploit-db.com/exploits/51096
References (7)
Scores
CVSS v3
9.8
EPSS
0.2921
EPSS Percentile
96.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
VulnCheck KEV
2025-06-20
CWE
CWE-78
Status
published
Products (2)
minidvblinux/minidvblinux
< 5.4
MiniDVBLinux/MiniDVBLinux
< 5.4
Published
Jun 20, 2025
Tracked Since
Feb 18, 2026