OpenDreambox 2.0.0 is susceptible to remote code execution via the webadmin plugin. Remote attackers can execute arbitrary OS commands via shell metacharacters in the command parameter to the /script URI in enigma2-plugins/blob/master/webadmin/src/WebChilds/Script.py.
id: CVE-2017-14135
info:
name: OpenDreambox 2.0.0 - Remote Code Execution
author: alph4byt3
s
...