CVE-2025-66254
Last modified
CVE-2025-66254 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Unauthenticated Arbitrary File Deletion (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform The deleteupgrade parameter allows unauthenticated deletion of arbitrary files. The `deleteupgrade` parameter in `/var/www/upgrade_contents.php` allows unauthenticated deletion of arbitrary files in `/var/www/upload/` without any extension restriction or path sanitization, enabling attackers to remove critical system files.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
Unauthenticated Arbitrary File Deletion (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform The deleteupgrade parameter allows unauthenticated deletion of arbitrary files. The `deleteupgrade` parameter in `/var/www/upgrade_contents.php` allows unauthenticated deletion of arbitrary files in `/var/www/upload/` without any extension restriction or path sanitization, enabling attackers to remove critical system files.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dbbroadcast | Mozart Next 100 Firmware | All versions |
| Dbbroadcast | Mozart Next 1000 Firmware | All versions |
| Dbbroadcast | Mozart Next 2000 Firmware | All versions |
| Dbbroadcast | Mozart Next 30 Firmware | All versions |
| Dbbroadcast | Mozart Next 300 Firmware | All versions |
| Dbbroadcast | Mozart Next 3000 Firmware | All versions |
| Dbbroadcast | Mozart Next 3500 Firmware | All versions |
| Dbbroadcast | Mozart Next 50 Firmware | All versions |
| Dbbroadcast | Mozart Next 500 Firmware | All versions |
| Dbbroadcast | Mozart Next 6000 Firmware | All versions |
| Dbbroadcast | Mozart Next 7000 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 30 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 50 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 100 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 300 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 500 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 1000 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 2000 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 3000 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 3500 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 6000 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 7000 Firmware | All versions |
References
- https://www.abdulmhsblog.com/posts/webfmvulns/Exploit, Third Party Advisory
- https://www.abdulmhsblog.com/posts/webfmvulns/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-66254?
How severe is CVE-2025-66254?
How do I fix CVE-2025-66254?
Are you affected by CVE-2025-66254?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
