PT-2025-48113 · Db Elettronica Telecomunicazioni Spa · Mozart Fm Transmitter

·

CVE-2025-66259

·

Published

2025-11-26

·

Updated

2025-12-24

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30 through 7000
Description The software contains a flaw that allows for remote code execution. An attacker with authentication can execute code due to insufficient input filtering. Specifically, user-supplied data related to hour and time, passed directly into a date shell command within the main ok.php file, is the root cause.
Recommendations Apply updates to versions prior to 7001.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-66259

Affected Products

Mozart Fm Transmitter