CVE-2023-53770
EUVD-2023-6018209.12.2025, 21:15
MiniDVBLinux 5.4 contains an unauthenticated configuration download vulnerability that allows remote attackers to access sensitive system configuration files through a direct object reference. Attackers can exploit the backup download endpoint by sending a GET request with 'action=getconfig' to retrieve a complete system configuration archive containing sensitive credentials.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| minidvblinux | minidvblinux | 𝑥 ≤ 5.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration