vendor:
MiniDVBLinux
by:
LiquidWorm
9.8
CVSS
CRITICAL
Remote Code Execution (RCE)
78
CWE
Product Name: MiniDVBLinux
Affected Version From: <=5.4
Affected Version To: <=5.4
Patch Exists: NO
Related CWE:
CPE: a:minidvblinux:minidvblinux
Platforms Tested: armhf, armhf-rpi2, GNU/Linux 4.19.127.203 (armv7l), VideoDiskRecorder 2.4.6
2022
MiniDVBLinux 5.4 Simple VideoDiskRecorder Protocol SVDRP – Remote Code Execution (RCE)
MiniDVBLinux 5.4 Simple VideoDiskRecorder Protocol SVDRP (svdrpsend.sh) Exploit allows the usage of the SVDRP protocol/commands to be sent by a remote attacker to manipulate and/or control remotely the TV.
Mitigation:
Ensure that the SVDRP protocol is not exposed to the public internet and is only accessible from trusted networks.