Fiche vulnérabilité
CVE-2025-66256 : faille critique dbbroadcast mozart next 100 firmware (CVSS 9.8)
Description
Unauthenticated Arbitrary File Upload (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Unrestricted file upload in patch_contents.php allows uploading malicious files. The `/var/tdf/patch_contents.php` endpoint allows unauthenticated arbitrary file uploads without file type validation, MIME checking, or size restrictions beyond 16MB, enabling attackers to upload malicious files.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 26 nov. 2025
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- dbbroadcast mozart next 100 firmware
- dbbroadcast mozart next 1000 firmware
- dbbroadcast mozart next 2000 firmware
- dbbroadcast mozart next 30 firmware
- dbbroadcast mozart next 300 firmware
- dbbroadcast mozart next 3000 firmware
- dbbroadcast mozart next 3500 firmware
- dbbroadcast mozart next 50 firmware
- dbbroadcast mozart next 500 firmware
- dbbroadcast mozart next 6000 firmware
- dbbroadcast mozart next 7000 firmware
- dbbroadcast mozart dds next 30 firmware
- dbbroadcast mozart dds next 50 firmware
- dbbroadcast mozart dds next 100 firmware
- dbbroadcast mozart dds next 300 firmware
- dbbroadcast mozart dds next 500 firmware
- dbbroadcast mozart dds next 1000 firmware
- dbbroadcast mozart dds next 2000 firmware
- dbbroadcast mozart dds next 3000 firmware
- dbbroadcast mozart dds next 3500 firmware