MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands as root through the command GET parameter. Attackers can exploit the /tpl/commands.sh endpoint by sending malicious command values to gain root-level system access.
In many cases, an attacker can leverage the conditions that cause unhandled exception errors in order to gain unauthorized access to the system.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Minidvblinux | Minidvblinux | 5.4 (including) | 5.4 (including) |