CVE-2022-50691
Unknown
Unknown - Not Provided
Remote Command Execution in MiniDVBLinux 5.4 via /tpl/commands.sh
Publication date: 2025-12-30
Last updated on: 2025-12-30
Assigner: VulnCheck
Description
Description
MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands as root through the 'command' GET parameter. Attackers can exploit the /tpl/commands.sh endpoint by sending malicious command values to gain root-level system access.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| minidvblinux | minidvblinux | 5.4 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-537 | In many cases, an attacker can leverage the conditions that cause unhandled exception errors in order to gain unauthorized access to the system. |