CVE-2025-66255

Unauthenticated Arbitrary File Upload (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Missing signature validation allows uploading malicious firmware packages.  The firmware upgrade endpoint in `upgrade_contents.php` accepts arbitrary file uploads without validating file headers, cryptographic signatures, or enforcing .tgz format requirements, allowing malicious firmware injection. This endpoint also subsequently provides ways for arbitrary file uploads and subsequent remote code execution
References
Link Resource
https://www.abdulmhsblog.com/posts/webfmvulns/ Exploit Third Party Advisory
https://www.abdulmhsblog.com/posts/webfmvulns/ Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_3000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_3000:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_3500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_3500:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_50_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_50:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_500:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_6000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_6000:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_7000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_7000:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_100:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_1000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_1000:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_2000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_2000:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_30_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_30:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_300:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_30_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_30:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_50_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_50:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_100:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_300:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_500:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_1000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_1000:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_2000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_2000:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_3000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_3000:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_3500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_3500:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_6000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_6000:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_7000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_7000:-:*:*:*:*:*:*:*

History

03 Dec 2025, 16:48

Type Values Removed Values Added
References () https://www.abdulmhsblog.com/posts/webfmvulns/ - () https://www.abdulmhsblog.com/posts/webfmvulns/ - Exploit, Third Party Advisory
First Time Dbbroadcast mozart Next 500
Dbbroadcast mozart Next 1000
Dbbroadcast mozart Dds Next 7000
Dbbroadcast mozart Dds Next 50
Dbbroadcast mozart Next 50 Firmware
Dbbroadcast mozart Dds Next 6000
Dbbroadcast mozart Next 7000 Firmware
Dbbroadcast mozart Next 30 Firmware
Dbbroadcast mozart Dds Next 300 Firmware
Dbbroadcast mozart Next 50
Dbbroadcast mozart Next 7000
Dbbroadcast mozart Dds Next 3500
Dbbroadcast mozart Dds Next 3500 Firmware
Dbbroadcast mozart Next 2000 Firmware
Dbbroadcast mozart Dds Next 500 Firmware
Dbbroadcast mozart Next 1000 Firmware
Dbbroadcast mozart Next 6000
Dbbroadcast mozart Dds Next 100 Firmware
Dbbroadcast mozart Dds Next 1000 Firmware
Dbbroadcast mozart Next 3500 Firmware
Dbbroadcast mozart Next 300
Dbbroadcast mozart Dds Next 6000 Firmware
Dbbroadcast
Dbbroadcast mozart Dds Next 2000
Dbbroadcast mozart Next 3000 Firmware
Dbbroadcast mozart Next 6000 Firmware
Dbbroadcast mozart Dds Next 100
Dbbroadcast mozart Dds Next 30
Dbbroadcast mozart Dds Next 500
Dbbroadcast mozart Dds Next 2000 Firmware
Dbbroadcast mozart Next 300 Firmware
Dbbroadcast mozart Next 100 Firmware
Dbbroadcast mozart Next 3000
Dbbroadcast mozart Dds Next 300
Dbbroadcast mozart Next 100
Dbbroadcast mozart Next 3500
Dbbroadcast mozart Dds Next 30 Firmware
Dbbroadcast mozart Dds Next 50 Firmware
Dbbroadcast mozart Next 500 Firmware
Dbbroadcast mozart Next 2000
Dbbroadcast mozart Dds Next 7000 Firmware
Dbbroadcast mozart Dds Next 1000
Dbbroadcast mozart Dds Next 3000 Firmware
Dbbroadcast mozart Next 30
Dbbroadcast mozart Dds Next 3000
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-434
CPE cpe:2.3:h:dbbroadcast:mozart_dds_next_3000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_50:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_7000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_2000:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_2000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_6000:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_3500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_500:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_3000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_1000:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_50_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_100:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_100:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_30:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_30:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_3000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_3500:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_500:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_30_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_3500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_6000:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_1000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_30_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_300:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_7000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_3500:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_50_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_2000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_3000:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_6000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_6000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_7000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_50:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_1000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_7000:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_1000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_2000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_300:-:*:*:*:*:*:*:*

03 Dec 2025, 16:15

Type Values Removed Values Added
References () https://www.abdulmhsblog.com/posts/webfmvulns/ - () https://www.abdulmhsblog.com/posts/webfmvulns/ -

26 Nov 2025, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-26 01:16

Updated : 2025-12-03 16:48


NVD link : CVE-2025-66255

Mitre link : CVE-2025-66255

CVE.ORG link : CVE-2025-66255


JSON object : View

Products Affected

dbbroadcast

  • mozart_next_3000_firmware
  • mozart_dds_next_1000_firmware
  • mozart_next_3500_firmware
  • mozart_next_300_firmware
  • mozart_dds_next_2000_firmware
  • mozart_dds_next_2000
  • mozart_dds_next_3500_firmware
  • mozart_next_30
  • mozart_dds_next_50
  • mozart_dds_next_6000
  • mozart_next_7000
  • mozart_dds_next_30_firmware
  • mozart_next_50_firmware
  • mozart_next_7000_firmware
  • mozart_next_100_firmware
  • mozart_dds_next_6000_firmware
  • mozart_next_2000
  • mozart_next_6000
  • mozart_next_2000_firmware
  • mozart_dds_next_30
  • mozart_dds_next_7000
  • mozart_next_50
  • mozart_next_6000_firmware
  • mozart_dds_next_300_firmware
  • mozart_next_1000
  • mozart_next_500_firmware
  • mozart_next_300
  • mozart_next_100
  • mozart_dds_next_100_firmware
  • mozart_dds_next_3500
  • mozart_dds_next_300
  • mozart_dds_next_3000
  • mozart_next_3500
  • mozart_dds_next_500_firmware
  • mozart_next_3000
  • mozart_dds_next_3000_firmware
  • mozart_dds_next_7000_firmware
  • mozart_dds_next_100
  • mozart_next_1000_firmware
  • mozart_dds_next_500
  • mozart_dds_next_50_firmware
  • mozart_next_30_firmware
  • mozart_dds_next_1000
  • mozart_next_500
CWE
CWE-345

Insufficient Verification of Data Authenticity

CWE-434

Unrestricted Upload of File with Dangerous Type