CVE-2025-66260

MEDIUM

DB Electronica Telecomunicazioni Mozart FM Transmitter - SQL Injection via status_sql.php sw1 and sw2 Parameters

Title source: llm
STIX 2.1

Description

PostgreSQL SQL Injection (status_sql.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform SQL injection via sw1 and sw2 parameters in status_sql.php. The `status_sql.php` endpoint constructs SQL UPDATE queries by directly concatenating user-controlled `sw1` and `sw2` parameters without using parameterized queries or `pg_escape_string()`. While PostgreSQL's `pg_exec` limitations prevent stacked queries, attackers can inject subqueries for data exfiltration and leverage verbose error messages for reconnaissance.

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit technical-description
https://www.abdulmhsblog.com/posts/webfmvulns/

Scores

CVSS v3 6.5
EPSS 0.0027
EPSS Percentile 18.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (22)
dbbroadcast/mozart_dds_next_1000_firmware
dbbroadcast/mozart_dds_next_100_firmware
dbbroadcast/mozart_dds_next_2000_firmware
dbbroadcast/mozart_dds_next_3000_firmware
dbbroadcast/mozart_dds_next_300_firmware
dbbroadcast/mozart_dds_next_30_firmware
dbbroadcast/mozart_dds_next_3500_firmware
dbbroadcast/mozart_dds_next_500_firmware
dbbroadcast/mozart_dds_next_50_firmware
dbbroadcast/mozart_dds_next_6000_firmware
... and 12 more
Published Nov 26, 2025
Tracked Since Feb 18, 2026