CVE 9.9 CRITICAL

Unauthenticated Arbitrary File Upload (upgrade_contents.php)_CVE-2025-66255

9.9 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:N/SA:N

Description

Unauthenticated Arbitrary File Upload (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Missing signature validation allows uploading malicious firmware packages.
The firmware upgrade endpoint in `upgrade_contents.php` accepts arbitrary file uploads without validating file headers, cryptographic signatures, or enforcing .tgz format requirements, allowing malicious firmware injection. This endpoint also subsequently provides ways for arbitrary file uploads and subsequent remote code execution

AI Analysis

Unauthenticated arbitrary file upload vulnerability in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter, allowing attackers to upload malicious firmware packages

Basic Information

ID CVE-2025-66255
Source Gridware
Published Nov 26, 2025 at 00:39

Affected Product

Vendor DB Electronica Telecomunicazioni S.p.A.
Product Mozart FM Transmitter
Version 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000
Affected Versions DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 30
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 50
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 100
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 300
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 500
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 1000
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 2000
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 3000
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 3500
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 6000
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 7000

CWE Classification

AI Assessment

AI Score 9.9 / 10
AI Severity Critical
Vendor DB Electronica Telecomunicazioni S.p.A.
Product Mozart FM Transmitter
Version 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.