PT-2025-50740 · Dizquetv · Dizquetv

Published

2025-12-11

·

Updated

2025-12-12

·

CVE-2024-58286

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions dizqueTV version 1.5.3
Description dizqueTV version 1.5.3 contains a remote code execution issue. An attacker can inject arbitrary commands through the FFMPEG Executable Path settings due to improper input validation. This allows modification of the executable path with shell commands, potentially enabling the reading of system files like /etc/passwd. The vulnerable setting is the FFMPEG Executable Path.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict modification of the FFMPEG Executable Path settings.

Exploit

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-58286

Affected Products

Dizquetv