CVE-2025-66253
CRITICALDB Electronica Telecomunicazioni Mozart FM Transmitter - Unauthenticated OS Command Injection via start_upgrade.php
Title source: llmDescription
Unauthenticated OS Command Injection (start_upgrade.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform User input passed directly to exec() allows remote code execution via start_upgrade.php. The `/var/tdf/start_upgrade.php` endpoint passes user-controlled `$_GET["filename"]` directly into `exec()` without sanitization or shell escaping. Attackers can inject arbitrary shell commands using metacharacters (`;`, `|`, etc.) to achieve remote code execution as the web server user (likely root).
References (1)
Core 1
Core References
Exploit, Third Party Advisory exploit
technical-description
https://www.abdulmhsblog.com/posts/webfmvulns/
Scores
CVSS v3
9.8
EPSS
0.0201
EPSS Percentile
78.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (22)
dbbroadcast/mozart_dds_next_1000_firmware
dbbroadcast/mozart_dds_next_100_firmware
dbbroadcast/mozart_dds_next_2000_firmware
dbbroadcast/mozart_dds_next_3000_firmware
dbbroadcast/mozart_dds_next_300_firmware
dbbroadcast/mozart_dds_next_30_firmware
dbbroadcast/mozart_dds_next_3500_firmware
dbbroadcast/mozart_dds_next_500_firmware
dbbroadcast/mozart_dds_next_50_firmware
dbbroadcast/mozart_dds_next_6000_firmware
... and 12 more
Published
Nov 26, 2025
Tracked Since
Feb 18, 2026