PT-2025-50267 · Unknown · Minidvblinux

Published

2025-12-09

·

Updated

2025-12-19

·

CVE-2023-53770

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MiniDVBLinux version 5.4
Description MiniDVBLinux version 5.4 has an issue allowing unauthenticated access to system configuration files. Remote attackers can obtain sensitive system configuration files through a direct object reference. The issue is exploitable by sending a GET request to the backup download endpoint with the parameter action set to getconfig, which retrieves a system configuration archive containing sensitive credentials. The affected API endpoint is '/backup/download'.
Recommendations Apply any available configuration changes to restrict access to the /backup/download endpoint. Restrict access to the getconfig action.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-53770

Affected Products

Minidvblinux