VYPR
High severity7.5NVD Advisory· Published Dec 9, 2025· Updated Jun 17, 2026

CVE-2023-53770

CVE-2023-53770

Description

MiniDVBLinux 5.4 contains an unauthenticated configuration download vulnerability that allows remote attackers to access sensitive system configuration files through a direct object reference. Attackers can exploit the backup download endpoint by sending a GET request with 'action=getconfig' to retrieve a complete system configuration archive containing sensitive credentials.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • MiniDVBLinux/MiniDVBLinux(TM) Distribution (MLD)v5
    Range: <=5.4
  • Minidvblinux/Minidvblinuxllm-fuzzy2 versions
    <5.4+ 1 more
    • (no CPE)range: <5.4
    • cpe:2.3:a:minidvblinux:minidvblinux:*:*:*:*:*:*:*:*range: <=5.4

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.