Unauthenticated Arbitrary File Deletion in Mozart FM Transmitter by DB Electronica Telecomunicazioni S.p.A.
CVE-2025-66254

7.8HIGH

Key Information:

Vendor
CVE Published:
26 November 2025

Badges

👾 Exploit Exists

What is CVE-2025-66254?

A vulnerability exists in the Mozart FM Transmitter by DB Electronica Telecomunicazioni S.p.A. that allows unauthenticated users to delete arbitrary files from the server. The weakness lies in the 'deleteupgrade' parameter of the 'upgrade_contents.php' script, which does not perform adequate checks, enabling attackers to remove critical files from the system. This flaw poses a significant risk as it could compromise the integrity and availability of the affected systems, allowing unauthorized file manipulation.

Affected Version(s)

Mozart FM Transmitter 30

Mozart FM Transmitter 50

Mozart FM Transmitter 100

References

CVSS V4

Score:
7.8
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdul Mhanni
.
CVE-2025-66254 : Unauthenticated Arbitrary File Deletion in Mozart FM Transmitter by DB Electronica Telecomunicazioni S.p.A.