ZeroHour

Vulnerabilities

27 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-53968
+3 in the same advisory: …53969 …53967 …53970
Screen SFT DAB 600/C Firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address

Screen SFT DAB 600/C Firmware 1.9.3 contains a session management vulnerability that allows attackers to bypass authentication controls by exploiting IP address session binding. Attackers can reuse the same IP address and issue unauthorized requests to the userManager API to remove user accounts without proper authentication.

NVD description · AI analysis pending
9.3
group max
<1% PoC ×3
  • dbbroadcast sft dab 600\/c firmware
CVE-2023-53776
+1 in the same advisory: …53775
Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to exploit weak session management by reusing IP-bound session identi

Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to exploit weak session management by reusing IP-bound session identifiers. Attackers can issue unauthorized requests to the device management API by leveraging the session binding mechanism to perform critical operations on the transmitter.

NVD description · AI analysis pending
8.7
group max
<1% PoC
  • dbbroadcast sft dab 600\/c firmware
CVE-2023-53740
+1 in the same advisory: …53741
Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current credential

Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current credentials. Attackers can exploit the userManager.cgx endpoint by sending a crafted JSON request with a new MD5-hashed password to directly modify the admin account.

NVD description · AI analysis pending
8.6
group max
<1% PoC ×2
  • dbbroadcast sft dab 015\/c firmware
  • dbbroadcast sft dab 050\/c firmware
  • dbbroadcast sft dab 150\/c firmware
  • +1 more
CVE-2025-66255
+1 in the same advisory: …66263
Unauthenticated Arbitrary File Upload (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A.

Unauthenticated Arbitrary File Upload (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Missing signature validation allows uploading malicious firmware packages. The firmware upgrade endpoint in `upgrade_contents.php` accepts arbitrary file uploads without validating file headers, cryptographic signatures, or enforcing .tgz format requirements, allowing malicious firmware injection. This endpoint also subsequently provides ways for arbitrary file uploads and subsequent remote code execution

NVD description · AI analysis pending
9.9
group max
<1% PoC
  • dbbroadcast mozart next 3000 firmware
  • dbbroadcast mozart next 3500 firmware
  • dbbroadcast mozart next 50 firmware
  • +1 more
CVE-2025-66261
Unauthenticated OS Command Injection (restore_settings.php) in DB Electronica Telecomunicazioni S.p.A.

Unauthenticated OS Command Injection (restore_settings.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform URL-decoded name parameter passed to exec() allows remote code execution. The `/var/tdf/restore_settings.php` endpoint passes user-controlled `$_GET["name"]` parameter through `urldecode()` directly into `exec()` without validation or escaping. Attackers can inject arbitrary shell commands using metacharacters (`;`, `|`, `&&`, etc.) to achieve unauthenticated remote code execution as the web server user.

NVD description · AI analysis pending
9.9
group max
2% PoC
  • dbbroadcast mozart next 100 firmware
  • dbbroadcast mozart next 1000 firmware
  • dbbroadcast mozart next 2000 firmware
  • +1 more
CVE-2025-66258
Stored Cross-Site Scripting via XML Injection in DB Electronica Telecomunicazioni S.p.A.

Stored Cross-Site Scripting via XML Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Stored XSS via crafted filenames injected into patchlist.xml. User-controlled filenames are directly concatenated into `patchlist.xml` without encoding, allowing injection of malicious JavaScript payloads via crafted filenames (e.g., ` .bin`). The XSS executes when ajax.js processes and renders the XML file.

NVD description · AI analysis pending
7.1<1% PoC
  • dbbroadcast mozart next 6000 firmware
  • dbbroadcast mozart next 500 firmware
  • dbbroadcast mozart next 50 firmware
  • +1 more
CVE-2025-63228
+2 in the same advisory: …63227 …63229
The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unauthenticated file upload vulnerability in the /upload_file.php endp

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unauthenticated file upload vulnerability in the /upload_file.php endpoint. An attacker can exploit this by sending a crafted POST request with a malicious file (e.g., a PHP webshell) to the server. The uploaded file is stored in the /upload/ directory, enabling remote code execution and full system compromise.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • dbbroadcast mozart next 100 firmware
  • dbbroadcast mozart next 1000 firmware
  • dbbroadcast mozart next 2000 firmware
  • +1 more
CVE-2023-7328
Screen SFT DAB 600/C firmware versions up to and including 1.9.3 contain an improper access control on the user management API allows unauthenticated requests t

Screen SFT DAB 600/C firmware versions up to and including 1.9.3 contain an improper access control on the user management API allows unauthenticated requests to retrieve structured user data, including account names and connection metadata such as client IP and timeout values.

NVD description · AI analysis pending
6.9<1% PoC ×2
  • dbbroadcast sft dab 600\/c firmware
CVE-2023-33684
Weak session management in DB Elettronica Telecomunicazioni SpA SFT DAB 600/C Firmware:

Weak session management in DB Elettronica Telecomunicazioni SpA SFT DAB 600/C Firmware: 1.9.3 Bios firmware: 7.1 (Apr 19 2021) Gui: 2.46 FPGA: 169.55 uc: 6.15 allows attackers on the same network to bypass authentication by re-using the IP address assigned to the device by the NAT protocol.

NVD description · AI analysis pending
5.7<1%
  • dbbroadcast sft dab 600\/c bios
  • dbbroadcast sft dab 600\/c firmware