VendorsDbbroadcastmozart_dds_next_6000_firmwareall versions
Vulnerabilities

Dbbroadcast DB Elettronica Telecomunicazioni SpA MOZART DDS NEXT 6000 Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2025-66261
Unauthenticated OS Command Injection (restore_settings.php)
Published 2025-11-26 · Analyzed
9.9EPSS 0.023
CVE-2025-66253
Unauthenticated OS Command Injection (start_upgrade.php)
Published 2025-11-26 · Analyzed
9.9EPSS 0.023
CVE-2025-66256
Unauthenticated Arbitrary File Upload (patch_contents.php)
Published 2025-11-26 · Modified
9.9EPSS 0.004
CVE-2025-66255
Unauthenticated Arbitrary File Upload (upgrade_contents.php)
Published 2025-11-26 · Analyzed
9.9EPSS 0.004
CVE-2025-66262
Arbitrary File Overwrite via Tar Extraction Path Traversal
Published 2025-11-26 · Analyzed
9.8EPSS 0.014
CVE-2025-63228
The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unauthenticated file upload vulnerability in the /upload_file.php endpoint. An attacker can exploit this by sending a crafted POST request with a malicious file (e.g., a PHP webshell) to the server. The uploaded file is stored in the /upload/ directory, enabling remote code execution and full system compromise.
Published 2025-11-18 · Analyzed
9.8EPSS 0.008
CVE-2025-66259
Authenticated Root Remote Code Execution through improper filtering of HTTP post request parameters
Published 2025-11-26 · Analyzed
9.8EPSS 0.007
CVE-2025-66250
Unauthenticated Arbitrary File Upload (status_contents.php)
Published 2025-11-26 · Analyzed
9.8EPSS 0.004
CVE-2025-66257
Unauthenticated Arbitrary File Deletion (patch_contents.php)
Published 2025-11-26 · Analyzed
9.2EPSS 0.004
CVE-2025-66251
Unauthenticated Path Traversal with Arbitrary File Deletion
Published 2025-11-26 · Analyzed
9.1EPSS 0.005
CVE-2025-66254
Unauthenticated Arbitrary File Deletion (upgrade_contents.php)
Published 2025-11-26 · Analyzed
9.1EPSS 0.004
CVE-2025-66263
Unauthenticated Arbitrary File Read via Null Byte Injection
Published 2025-11-26 · Analyzed
8.9EPSS 0.004
CVE-2025-66252
Infinite Loop Denial of Service via Failed File Deletion
Published 2025-11-26 · Analyzed
8.4EPSS 0.004
CVE-2025-63227
The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulnerability in the /patch.php endpoint. An attacker with administrative credentials can upload arbitrary files (e.g., PHP webshells), which are stored in the /patch/ directory. This allows the attacker to execute arbitrary commands on the server, potentially leading to full system compromise.
Published 2025-11-18 · Analyzed
7.2EPSS 0.006
CVE-2025-66260
PostgreSQL SQL Injection (status_sql.php)
Published 2025-11-26 · Analyzed
7.2EPSS 0.003
CVE-2025-66258
Stored Cross-Site Scripting via XML Injection
Published 2025-11-26 · Analyzed
7.1EPSS 0.002
CVE-2025-63229
The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains a reflected Cross-Site Scripting (XSS) vulnerability in the /main0.php endpoint. By injecting a malicious JavaScript payload into the ?m= query parameter, an attacker can execute arbitrary code in the victim's browser, potentially stealing sensitive information, hijacking sessions, or performing unauthorized actions.
Published 2025-11-18 · Analyzed
5.4EPSS 0.003