vendor:
MiniDVBLinux
by:
LiquidWorm
9.8
CVSS
CRITICAL
Remote Root Command Injection
78
CWE
Product Name: MiniDVBLinux
Affected Version From: <=5.4
Affected Version To: <=5.4
Patch Exists: YES
Related CWE: ZSL-2022-5717
CPE: a:minidvblinux:minidvblinux:5.4
Platforms Tested: armhf, armhf-rpi2, GNU/Linux 4.19.127.203 (armv7l), VideoDiskRecorder 2.4.6
2022
MiniDVBLinux 5.4 – Remote Root Command Injection
The application suffers from an OS command injection vulnerability. This can be exploited to execute arbitrary commands with root privileges.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in system commands.