PT-2025-47398 · Unknown · Mozart Fm Transmitter

Published

2025-11-18

·

Updated

2025-11-19

·

CVE-2025-63227

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mozart FM Transmitter version WEBMOZZI-00287
Description The Mozart FM Transmitter web management interface version WEBMOZZI-00287 has an unrestricted file upload issue in the /patch.php endpoint. An attacker with administrative access can upload arbitrary files, such as PHP webshells, to the /patch/ directory. Successful exploitation allows the attacker to execute arbitrary commands on the server, potentially resulting in full system compromise.
Recommendations Apply restrictions to file uploads in the /patch.php endpoint. Restrict administrative access to the web management interface.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-63227

Affected Products

Mozart Fm Transmitter