PT-2025-48113 · Db Elettronica Telecomunicazioni Spa · Mozart Fm Transmitter
Abdul Mhanni
·
Published
2025-11-26
·
Updated
2025-12-24
·
CVE-2025-66259
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30 through 7000
Description
The software contains a flaw that allows for remote code execution. An attacker with authentication can execute code due to insufficient input filtering. Specifically, user-supplied data related to hour and time, passed directly into a date shell command within the
main ok.php file, is the root cause.Recommendations
Apply updates to versions prior to 7001.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mozart Fm Transmitter