Unauthenticated Arbitrary File Read in DB Electronica's Mozart FM Transmitter
CVE-2025-66263
Key Information:
- Status
- Vendor
- CVE Published:
- 26 November 2025
Badges
What is CVE-2025-66263?
The Mozart FM Transmitter from DB Electronica Telecomunicazioni S.p.A. is susceptible to an unauthenticated arbitrary file read vulnerability due to a critical flaw in the download_setting.php script. This vulnerability allows an attacker to exploit null byte injection to bypass file extension restrictions and perform directory traversal. By manipulating the filename parameter, attackers can access sensitive files on the server, including the system password file. This issue primarily affects versions running on PHP 5.3.2 and lower, where the handling of null bytes permits unauthorized disclosure of any file readable by the web server user.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mozart FM Transmitter 30
Mozart FM Transmitter 50
Mozart FM Transmitter 100
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
