Unauthenticated Arbitrary File Deletion in Mozart FM Transmitter by DB Electronica Telecomunicazioni S.p.A.
CVE-2025-66254
7.8HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 26 November 2025
Badges
👾 Exploit Exists
What is CVE-2025-66254?
A vulnerability exists in the Mozart FM Transmitter by DB Electronica Telecomunicazioni S.p.A. that allows unauthenticated users to delete arbitrary files from the server. The weakness lies in the 'deleteupgrade' parameter of the 'upgrade_contents.php' script, which does not perform adequate checks, enabling attackers to remove critical files from the system. This flaw poses a significant risk as it could compromise the integrity and availability of the affected systems, allowing unauthorized file manipulation.
Affected Version(s)
Mozart FM Transmitter 30
Mozart FM Transmitter 50
Mozart FM Transmitter 100
References
CVSS V4
Score:
7.8
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Abdul Mhanni
