PT-2025-50270 · Unknown · Minidvblinux
Published
2025-12-09
·
Updated
2025-12-10
·
CVE-2023-53773
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MiniDVBLinux version 5.4
Description
The software contains an unauthenticated issue in the
tv action.sh script. This allows remote attackers to generate live stream snapshots using the Simple VDR Protocol. Attackers can request the /tpl/tv action.sh endpoint to create and retrieve a live TV screenshot stored in /var/www/images/tv.jpg without needing to authenticate.Recommendations
Apply any available updates to address the issue in the
tv action.sh script.
As a temporary workaround, restrict access to the /tpl/tv action.sh endpoint.Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Minidvblinux