CVE-2024-51442

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jan 8, 2025
CWE ID 77

Summary

CVE-2024-51442 is a command injection vulnerability impacting Minidlna versions prior to v1.3.4. An attacker can exploit this issue by crafting a malicious minidlna.conf file, allowing them to execute arbitrary OS commands and potentially gain unauthorized access or control over the affected system. This vulnerability poses a significant risk to systems running the affected Minidlna version and necessitates immediate updating to a patched release.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share