ZeroHour

CVE-2025-66254

PoC
CVSS 4.0
7.8 high
EPSS
<1%p32
Published
()
Modified
Description

Unauthenticated Arbitrary File Deletion (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform The deleteupgrade parameter allows unauthenticated deletion of arbitrary files. The `deleteupgrade` parameter in `/var/www/upgrade_contents.php` allows unauthenticated deletion of arbitrary files in `/var/www/upload/` without any extension restriction or path sanitization, enabling attackers to remove critical system files.

Vendors
dbbroadcast
Products
mozart next 100 firmware, mozart next 1000 firmware, mozart next 2000 firmware, mozart next 30 firmware, mozart next 300 firmware, mozart next 3000 firmware, mozart next 3500 firmware, mozart next 50 firmware, mozart next 500 firmware, mozart next 6000 firmware, mozart next 7000 firmware, mozart dds next 30 firmware
Weakness
CWE-73
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.