CVE-2023-53770CWE-260

MiniDVBLinux 5.4 Unauthenticated Configuration Download via Backup Endpoint

High · published December 9, 2025

CVSS v4.0
8.7
EPSS
1%
Percentile
43.5
In the wild
Unconfirmed
What it is

⚡ A single unauthenticated GET request is all it takes to access sensitive system configurations in MiniDVBLinux 5.4! This vulnerability is like leaving the blueprints of your house unattended on the front porch, inviting anyone to take a peek inside. 🔓 Think of it as a delivery driver who, instead of checking the address, just hands over all the confidential documents in the package to anyone who asks. The backup download endpoint can be exploited without any identity verification, making it alarmingly easy for attackers to grab sensitive info. An attacker could retrieve the entire system configuration archive, uncovering sensitive credentials and potentially gaining full control over the system. This could lead to devastating consequences, like unauthorized access to critical services or data breaches that affect the entire organization.

Put simply

Think of it as a delivery driver who, instead of checking the address, just hands over all the confidential documents in the package to anyone who asks. The backup download endpoint can be exploited without any identity verification, making it alarmingly easy for attackers to grab sensitive info. This vulnerability allows unauthorized users to exploit a direct object reference in MiniDVBLinux, enabling them to send a GET request with 'action=getconfig' to download sensitive configuration files without authentication.

What to do

An attacker could retrieve the entire system configuration archive, uncovering sensitive credentials and potentially gaining full control over the system. This could lead to devastating consequences, like unauthorized access to critical services or data breaches that affect the entire organization. Immediate action is required! Upgrade to the latest version of MiniDVBLinux to patch this vulnerability. Additionally, consider implementing stricter access controls to prevent unauthorized requests to sensitive endpoints. You've got this! Stay proactive in securing your systems, and with these steps, you'll be a security hero in no time! 🛡️

The record
Technical detail
CVSS v4.0
8.7 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS
0.00542 · 43.5th percentile
Weakness
CWE-260 · Password in Configuration File
Published
2025-12-09T20:53Z
EPSS history
Timeline
  • 09 DEC 20:53Z
    MiniDVBLinux 5.4 Unauthenticated Configuration Download via Backup Endpoint
    cvelistv5