CVE 9.9 CRITICAL

Unauthenticated Arbitrary File Upload (patch_contents.php)_CVE-2025-66256

9.9 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:N/SA:N

Description

Unauthenticated Arbitrary File Upload (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Unrestricted file upload in patch_contents.php allows uploading malicious files.

The `/var/tdf/patch_contents.php` endpoint allows unauthenticated arbitrary file uploads without file type validation, MIME checking, or size restrictions beyond 16MB, enabling attackers to upload malicious files.

AI Analysis

Unauthenticated arbitrary file upload vulnerability in Mozart FM Transmitter, allowing attackers to upload malicious files.

Basic Information

ID CVE-2025-66256
Source Gridware
Published Nov 26, 2025 at 00:41

Affected Product

Vendor DB Electronica Telecomunicazioni S.p.A.
Product Mozart FM Transmitter
Version 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000
Affected Versions DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 30
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 50
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 100
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 300
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 500
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 1000
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 2000
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 3000
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 3500
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 6000
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter 7000

CWE Classification

AI Assessment

AI Score 9.9 / 10
AI Severity Critical
Vendor DB Electronica Telecomunicazioni S.p.A.
Product Mozart FM Transmitter
Version 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.