📦 Mozart Dds Next 1000 Firmware

by Dbbroadcast

🔍 What is Mozart Dds Next 1000 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-66259

CRITICAL CVSS 9.8 Nov 26, 2025

This vulnerability allows authenticated attackers to execute arbitrary commands with root privileges on DB Electronica Telecomunicazioni Mozart FM Transmitters. Attackers can inject malicious input in...

CVE-2025-66257

CRITICAL CVSS 9.1 Nov 26, 2025

This vulnerability allows unauthenticated attackers to delete arbitrary files in the /var/www/patch/ directory of Mozart FM Transmitter devices. Attackers can exploit the deletepatch parameter in patc...

CVE-2025-66261

CRITICAL CVSS 9.8 Nov 26, 2025

This CVE describes an unauthenticated OS command injection vulnerability in DB Electronica Telecomunicazioni Mozart FM Transmitters. Attackers can execute arbitrary shell commands on affected devices ...

CVE-2025-66262

CRITICAL CVSS 9.8 Nov 26, 2025

This vulnerability allows attackers to overwrite arbitrary system files via path traversal in tar archive extraction. Attackers can craft malicious .tgz archives that, when processed by the vulnerable...

CVE-2025-66251

CRITICAL CVSS 9.1 Nov 26, 2025

This vulnerability allows unauthenticated attackers to delete arbitrary .tgz files via path traversal in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitters. Attackers can exploit the delet...

CVE-2025-66253

CRITICAL CVSS 9.8 Nov 26, 2025

This vulnerability allows unauthenticated attackers to execute arbitrary operating system commands on DB Electronica Telecomunicazioni Mozart FM Transmitters by exploiting improper input sanitization ...

CVE-2025-66254

CRITICAL CVSS 9.1 Nov 26, 2025

This vulnerability allows unauthenticated attackers to delete arbitrary files from the /var/www/upload/ directory on affected Mozart FM Transmitters. Attackers can exploit the deleteupgrade parameter ...

CVE-2025-66255

CRITICAL CVSS 9.8 Nov 26, 2025

This vulnerability allows unauthenticated attackers to upload malicious firmware files to Mozart FM Transmitter devices, potentially leading to remote code execution. It affects all listed models (30,...

CVE-2025-66256

CRITICAL CVSS 9.8 Nov 26, 2025

This vulnerability allows unauthenticated attackers to upload arbitrary files to Mozart FM Transmitter devices via the patch_contents.php endpoint. Attackers can upload malicious files including websh...

CVE-2025-66250

CRITICAL CVSS 9.8 Nov 26, 2025

This vulnerability allows unauthenticated attackers to upload arbitrary files to DB Electronica Telecomunicazioni's Mozart FM Transmitter devices via the status_contents.php endpoint. Attackers can po...

CVE-2025-63228

CRITICAL CVSS 9.8 Nov 18, 2025

The Mozart FM Transmitter web management interface contains an unauthenticated file upload vulnerability that allows attackers to upload malicious files like PHP webshells without authentication. This...

CVE-2025-66263

HIGH CVSS 7.5 Nov 26, 2025

This vulnerability allows unauthenticated attackers to read arbitrary files on DB Electronica Telecomunicazioni Mozart FM Transmitters by exploiting null byte injection in PHP 5.3.2. Attackers can byp...

CVE-2025-66252

HIGH CVSS 7.5 Nov 26, 2025

This vulnerability allows attackers to cause a denial of service (DoS) by triggering an infinite loop in Mozart FM Transmitter software when file deletion fails. An attacker can exploit this by target...

CVE-2025-63227

HIGH CVSS 7.2 Nov 18, 2025

This vulnerability allows authenticated attackers with administrative credentials to upload arbitrary files to the Mozart FM Transmitter web management interface. The uploaded files can be executed on...

CVE-2025-66258

MEDIUM CVSS 5.4 Nov 26, 2025

This vulnerability allows attackers to inject malicious JavaScript into the Mozart FM Transmitter's patchlist.xml file through crafted filenames. When the system processes this XML file, the JavaScrip...

CVE-2025-66260

MEDIUM CVSS 6.5 Nov 26, 2025

This SQL injection vulnerability in DB Electronica Telecomunicazioni's Mozart FM Transmitter allows attackers to execute arbitrary SQL queries via the status_sql.php endpoint. Attackers can exfiltrate...

CVE-2025-63229

MEDIUM CVSS 5.4 Nov 18, 2025

This reflected XSS vulnerability in the Mozart FM Transmitter web interface allows attackers to inject malicious JavaScript via the ?m= parameter in /main0.php. When victims visit a crafted URL, attac...