Unauthenticated Arbitrary File Deletion in Mozart FM Transmitter by DB Electronica Telecomunicazioni S.p.A.
CVE-2025-66254
Key Information:
- Status
- Vendor
- CVE Published:
- 26 November 2025
Badges
What is CVE-2025-66254?
A vulnerability exists in the Mozart FM Transmitter by DB Electronica Telecomunicazioni S.p.A. that allows unauthenticated users to delete arbitrary files from the server. The weakness lies in the 'deleteupgrade' parameter of the 'upgrade_contents.php' script, which does not perform adequate checks, enabling attackers to remove critical files from the system. This flaw poses a significant risk as it could compromise the integrity and availability of the affected systems, allowing unauthorized file manipulation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mozart FM Transmitter 30
Mozart FM Transmitter 50
Mozart FM Transmitter 100
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
