vendor:
MiniDVBLinux
by:
LiquidWorm
7.5
CVSS
HIGH
Change Root Password
287
CWE
Product Name: MiniDVBLinux
Affected Version From: <=5.4
Affected Version To: <=5.4
Patch Exists: NO
Related CWE:
CPE: a:minidvblinux:minidvblinux:5.4
Platforms Tested: armhf, armhf-rpi2, GNU/Linux 4.19.127.203 (armv7l), VideoDiskRecorder 2.4.6
2022
MiniDVBLinux 5.4 – Change Root Password
The application allows a remote attacker to change the root password of the system without authentication (disabled by default) and verification of previously assigned credential. Command execution also possible using several POST parameters.
Mitigation:
Disable remote access to the application and ensure that authentication is enabled.