PT-2025-48113 · Db Elettronica Telecomunicazioni Spa · Mozart Fm Transmitter
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30 through 7000
Description
The software contains a flaw that allows for remote code execution. An attacker with authentication can execute code due to insufficient input filtering. Specifically, user-supplied data related to hour and time, passed directly into a date shell command within the
main ok.php file, is the root cause.Recommendations
Apply updates to versions prior to 7001.
Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mozart Fm Transmitter