CVE-2025-25038
Published: 20 June 2025
Summary
CVE-2025-25038 is a critical-severity OS Command Injection (CWE-78) vulnerability in Minidvblinux Minidvblinux. Its CVSS base score is 9.3 (Critical).
Operationally, ranked in the top 3.3% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
Deeper analysis
An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system's web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands, as indicated by the associated CWE-78 classification. This flaw received a CVSS 4.0 score of 9.3.
A remote unauthenticated attacker can exploit the issue over the network to execute arbitrary commands as the root user, potentially compromising the entire device. Exploitation evidence was observed by the Shadowserver Foundation on 2024-04-10 UTC, and the EPSS score stands at 0.2921.
Public references including exploit-db, packetstormsecurity, and vulncheck entries document the command injection vector, while Fortiguard lists a corresponding IPS signature.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-18780
Vulnerability details
An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management interface fails to properly sanitize user-supplied input before passing it to operating system commands. A remote unauthenticated attacker can exploit this vulnerability to execute…
more
arbitrary commands as the root user, potentially compromising the entire device. Exploitation evidence was observed by the Shadowserver Foundation on 2024-04-10 UTC.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
Likely Mitigating Controls AI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.