CVE-2025-66259
Last modified
CVE-2025-66259 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. Authenticated Root Remote Code Execution via improrer user input filtering in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform in main_ok.php user supplied data/hour/time is passed directly into date shell command. EPSS estimates a 0.58% chance of exploitation in the next 30 days.
Description
Authenticated Root Remote Code Execution via improrer user input filtering in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform in main_ok.php user supplied data/hour/time is passed directly into date shell command
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dbbroadcast | Mozart Next 100 Firmware | All versions |
| Dbbroadcast | Mozart Next 1000 Firmware | All versions |
| Dbbroadcast | Mozart Next 2000 Firmware | All versions |
| Dbbroadcast | Mozart Next 30 Firmware | All versions |
| Dbbroadcast | Mozart Next 300 Firmware | All versions |
| Dbbroadcast | Mozart Next 3000 Firmware | All versions |
| Dbbroadcast | Mozart Next 3500 Firmware | All versions |
| Dbbroadcast | Mozart Next 50 Firmware | All versions |
| Dbbroadcast | Mozart Next 500 Firmware | All versions |
| Dbbroadcast | Mozart Next 6000 Firmware | All versions |
| Dbbroadcast | Mozart Next 7000 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 30 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 50 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 100 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 300 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 500 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 1000 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 2000 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 3000 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 3500 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 6000 Firmware | All versions |
| Dbbroadcast | Mozart Dds Next 7000 Firmware | All versions |
References
- https://www.abdulmhsblog.com/posts/webfmvulns/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-66259?
How severe is CVE-2025-66259?
How do I fix CVE-2025-66259?
Are you affected by CVE-2025-66259?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
