PT-2025-50267 · Unknown · Minidvblinux
Published
2025-12-09
·
Updated
2025-12-19
·
CVE-2023-53770
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MiniDVBLinux version 5.4
Description
MiniDVBLinux version 5.4 has an issue allowing unauthenticated access to system configuration files. Remote attackers can obtain sensitive system configuration files through a direct object reference. The issue is exploitable by sending a GET request to the backup download endpoint with the parameter
action set to getconfig, which retrieves a system configuration archive containing sensitive credentials. The affected API endpoint is '/backup/download'.Recommendations
Apply any available configuration changes to restrict access to the
/backup/download endpoint.
Restrict access to the getconfig action.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Minidvblinux