CVE-2025-66252
Last modified
CVE-2025-66252 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. Infinite Loop Denial of Service via Failed File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Infinite loop when unlink() fails in status_contents.php causing DoS. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Infinite Loop Denial of Service via Failed File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Infinite loop when unlink() fails in status_contents.php causing DoS. Due to the fact that the unlink operation is done in a while loop; if an immutable file is specified or otherwise a file in which the process has no permissions to delete; it would repeatedly attempt to do in a loop.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dbbroadcast | Mozart Next 100 Firmware | All versions |
| Dbbroadcast | Mozart Next 1000 Firmware | All versions |
| Dbbroadcast | Mozart Next 2000 Firmware | All versions |
| Dbbroadcast | Mozart Next 30 Firmware | All versions |
| Dbbroadcast | Mozart Next 300 Firmware | All versions |
| Dbbroadcast | Mozart Next 3000 Firmware | All versions |
| Dbbroadcast | Mozart Next 3500 Firmware | All versions |
| Dbbroadcast | Mozart Next 50 Firmware | All versions |
| Dbbroadcast | Mozart Next 500 Firmware | All versions |
| Dbbroadcast | Mozart Next 6000 Firmware | All versions |
| Dbbroadcast | Mozart Next 7000 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 30 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 50 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 100 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 300 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 500 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 1000 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 2000 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 3000 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 3500 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 6000 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 7000 Firmware | All versions |
References
- https://www.abdulmhsblog.com/posts/webfmvulns/Exploit, Third Party Advisory
- https://www.abdulmhsblog.com/posts/webfmvulns/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-66252?
How severe is CVE-2025-66252?
How do I fix CVE-2025-66252?
Are you affected by CVE-2025-66252?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
