Cyber Resilience

CVE-2025-25038

CriticalPublic PoCRCE

Published: 20 June 2025

Published
20 June 2025
Modified
22 December 2025
KEV Added
Patch
CVSS Score v4 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score 0.2921 96.7th percentile
Risk Priority 36 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2025-25038 is a critical-severity OS Command Injection (CWE-78) vulnerability in Minidvblinux Minidvblinux. Its CVSS base score is 9.3 (Critical).

Operationally, ranked in the top 3.3% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

Deeper analysis

An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system's web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands, as indicated by the associated CWE-78 classification. This flaw received a CVSS 4.0 score of 9.3.

A remote unauthenticated attacker can exploit the issue over the network to execute arbitrary commands as the root user, potentially compromising the entire device. Exploitation evidence was observed by the Shadowserver Foundation on 2024-04-10 UTC, and the EPSS score stands at 0.2921.

Public references including exploit-db, packetstormsecurity, and vulncheck entries document the command injection vector, while Fortiguard lists a corresponding IPS signature.

EU & UK References

Vulnerability details

An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execute…

more

arbitrary commands as the root user, potentially compromising the entire device. Exploitation evidence was observed by the Shadowserver Foundation on 2024-04-10 UTC.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

minidvblinux
minidvblinux
≤ 5.4

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-78

Platform-independent apps typically execute inside a managed runtime or sandbox that restricts direct OS command execution, reducing the ability to exploit OS command injection.

addresses: CWE-78

Validates inputs to block special elements that would alter OS command execution.

References