Remote Command Execution Vulnerability in MiniDVBLinux 5.4 by Zero Science Lab
CVE-2022-50691
Key Information:
- Vendor
Minidvblinux
- Status
- Vendor
- CVE Published:
- 30 December 2025
Badges
What is CVE-2022-50691?
MiniDVBLinux version 5.4 contains a significant remote command execution vulnerability that enables unauthenticated attackers to execute arbitrary commands with root privileges. By exploiting the vulnerable '/tpl/commands.sh' endpoint, attackers can manipulate the 'command' GET parameter, allowing them to pass malicious inputs and gain unauthorized root access to the system. This vulnerability poses a serious risk as it could lead to complete system compromise and unauthorized data manipulation.
Affected Version(s)
MiniDVBLinux Unknown <= 5.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
