CVE-2025-66255
PoC —CVSS 4.0
9.9 critical
EPSS
<1%p31
Published
()
Modified
Description
Unauthenticated Arbitrary File Upload (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Missing signature validation allows uploading malicious firmware packages. The firmware upgrade endpoint in `upgrade_contents.php` accepts arbitrary file uploads without validating file headers, cryptographic signatures, or enforcing .tgz format requirements, allowing malicious firmware injection. This endpoint also subsequently provides ways for arbitrary file uploads and subsequent remote code execution
- Vendors
- dbbroadcast
- Products
- mozart next 3000 firmware, mozart next 3500 firmware, mozart next 50 firmware, mozart next 500 firmware, mozart next 6000 firmware, mozart next 7000 firmware, mozart next 100 firmware, mozart next 1000 firmware, mozart next 2000 firmware, mozart next 30 firmware, mozart next 300 firmware, mozart dds next 30 firmware
- Weakness
- CWE-345, CWE-434
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.