Unauthenticated Arbitrary File Upload Vulnerability in DB Electronica Telecomunicazioni Mozart FM Transmitter
CVE-2025-66255
Key Information:
- Status
- Vendor
- CVE Published:
- 26 November 2025
Badges
What is CVE-2025-66255?
The Mozart FM Transmitter from DB Electronica Telecomunicazioni contains a vulnerability in the 'upgrade_contents.php' endpoint, which allows unauthenticated users to upload arbitrary files. This flaw stems from a lack of validation for file headers and cryptographic signatures, combined with the absence of enforced .tgz file format requirements. As a result, attackers can exploit this vulnerability to inject malicious firmware packages, potentially leading to remote code execution on affected devices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mozart FM Transmitter 30
Mozart FM Transmitter 50
Mozart FM Transmitter 100
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
