High severity7.5NVD Advisory· Published Dec 9, 2025· Updated Jun 17, 2026
CVE-2023-53770
CVE-2023-53770
Description
MiniDVBLinux 5.4 contains an unauthenticated configuration download vulnerability that allows remote attackers to access sensitive system configuration files through a direct object reference. Attackers can exploit the backup download endpoint by sending a GET request with 'action=getconfig' to retrieve a complete system configuration archive containing sensitive credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- MiniDVBLinux/MiniDVBLinux(TM) Distribution (MLD)v5Range: <=5.4
<5.4+ 1 more
- (no CPE)range: <5.4
- cpe:2.3:a:minidvblinux:minidvblinux:*:*:*:*:*:*:*:*range: <=5.4
Patches
Vulnerability mechanics
References
4- www.exploit-db.com/exploits/51091nvdExploitThird Party AdvisoryVDB Entry
- www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5713.phpnvdExploitThird Party Advisory
- www.vulncheck.com/advisories/minidvblinux-unauthenticated-configuration-download-via-backup-endpointnvdThird Party Advisory
- www.minidvblinux.denvdProduct
News mentions
0No linked articles in our index yet.