Skip to main content

CVE-2025-34101

CVSS Score Not Available
68.85%
MEDIUM RiskEPSS (99th percentile)

An unauthenticated command injection vulnerability exists in Serviio Media Server versions 1.4 through 1.8 on Windows, in the /rest/action API endpoint exposed by the console component (default port 23423). The checkStreamUrl method accepts a VIDEO parameter that is passed unsanitized to a call to cmd.exe, enabling arbitrary command execution under the privileges of the web server. No authentication is required to exploit this issue, as the REST API is exposed by default and lacks access controls.

Published: 7/10/2025
Modified: 4/15/2026
Back to CVE Lookup

Vulnerability Summary

EPSS Score (Exploitation Probability)

68.85%MEDIUM Exploitation Risk
99th percentile

This vulnerability has a 68.85% probability of being exploited in the next 30 days, ranking higher than 99% of all scored CVEs.

CWE Classification

Related Vulnerabilities