Unauthenticated OS Command Injection in DB Electronica Telecomunicazioni Mozart FM Transmitter
CVE-2025-66253
9.9CRITICAL
Key Information:
- Status
- Vendor
- CVE Published:
- 26 November 2025
Badges
👾 Exploit Exists
What is CVE-2025-66253?
The DB Electronica Telecomunicazioni Mozart FM Transmitter is susceptible to an unauthenticated OS command injection vulnerability via the start_upgrade.php endpoint. This vulnerability arises because user input is passed directly to the exec() function without proper sanitization or escaping. An attacker can exploit this flaw by injecting arbitrary shell commands through specially crafted inputs, compromising the system and allowing remote code execution with the privileges of the web server user.
Affected Version(s)
Mozart FM Transmitter 30
Mozart FM Transmitter 50
Mozart FM Transmitter 100
References
CVSS V4
Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Abdul Mhanni
