CVE 9.3 CRITICAL

Authenticated Root Remote Code Execution through improper filtering of HTTP post request parameters_CVE-2025-66259

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

Description

Authenticated Root Remote Code Execution via improper user input filtering in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform in main_ok.php user supplied data/hour/time is passed directly into date shell command

AI Analysis

Authenticated Root Remote Code Execution via improper user input filtering

Basic Information

ID CVE-2025-66259
Source Gridware
Published Nov 26, 2025 at 00:46
Modified Nov 26, 2025 at 01:02

Affected Product

Vendor DB Electronica Telecomunicazioni S.p.A.
Product Mozart FM Transmitter
Version 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000
Affected Versions DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 30
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 50
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 100
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 300
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 500
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 1000
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 2000
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 3000
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 3500
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 6000
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 7000

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor DB Electronica Telecomunicazioni S.p.A.
Product Mozart FM Transmitter
Version 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.