Unauthenticated OS Command Injection in DB Electronica Telecomunicazioni Mozart FM Transmitter
CVE-2025-66253

9.9CRITICAL

Key Information:

Vendor
CVE Published:
26 November 2025

Badges

👾 Exploit Exists

What is CVE-2025-66253?

The DB Electronica Telecomunicazioni Mozart FM Transmitter is susceptible to an unauthenticated OS command injection vulnerability via the start_upgrade.php endpoint. This vulnerability arises because user input is passed directly to the exec() function without proper sanitization or escaping. An attacker can exploit this flaw by injecting arbitrary shell commands through specially crafted inputs, compromising the system and allowing remote code execution with the privileges of the web server user.

Affected Version(s)

Mozart FM Transmitter 30

Mozart FM Transmitter 50

Mozart FM Transmitter 100

References

CVSS V4

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdul Mhanni
.
CVE-2025-66253 : Unauthenticated OS Command Injection in DB Electronica Telecomunicazioni Mozart FM Transmitter