Description
MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands as root through the 'command' GET parameter. Attackers can exploit the /tpl/commands.sh endpoint by sending malicious command values to gain root-level system access.
Problem types
Java Runtime Error Message Containing Sensitive Information
Product status
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5718.php (Zero Science Lab Disclosure (ZSL-2022-5718))
packetstormsecurity.com/files/168749/ (Packet Storm Security Exploit Entry)
www.vulncheck.com/...e-root-command-execution-via-commandssh (VulnCheck Advisory: MiniDVBLinux 5.4 Remote Root Command Execution via commands.sh)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.