CVE Feed

    Dashboard / CVE / CVE-2025-66261

    CVE-2025-66261

    Unauthenticated OS Command Injection (restore_settings.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform URL-decoded name parameter passed to exec() allows remote code execution. The `/var/tdf/restore_settings.php` endpoint passes user-controlled `$_GET["name"]` parameter through `urldecode()` directly into `exec()` without validation or escaping. Attackers can inject arbitrary shell commands using metacharacters (`;`, `|`, `&&`, etc.) to achieve unauthenticated remote code execution as the web server user.

    Published:Nov 26, 2025
    Last Modified:Dec 3, 2025
    EPS:Nov 26, 2025
    EPSS Score:0.01303
    CVSS Score:9.8

    Affected Products

    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 100
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 1000
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 1000 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 100 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 2000
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 2000 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 30
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 300
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 3000
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 3000 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 300 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 30 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 3500
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 3500 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 50
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 500
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 500 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 50 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 6000
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 6000 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 7000
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 7000 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Fm Transmitter
    Vendor
    Dbbroadcast
    Product
    Mozart Next 100
    Vendor
    Dbbroadcast
    Product
    Mozart Next 1000
    Vendor
    Dbbroadcast
    Product
    Mozart Next 1000 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Next 100 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Next 2000
    Vendor
    Dbbroadcast
    Product
    Mozart Next 2000 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Next 30
    Vendor
    Dbbroadcast
    Product
    Mozart Next 300
    Vendor
    Dbbroadcast
    Product
    Mozart Next 3000
    Vendor
    Dbbroadcast
    Product
    Mozart Next 3000 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Next 300 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Next 30 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Next 3500
    Vendor
    Dbbroadcast
    Product
    Mozart Next 3500 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Next 50
    Vendor
    Dbbroadcast
    Product
    Mozart Next 500
    Vendor
    Dbbroadcast
    Product
    Mozart Next 500 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Next 50 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Next 6000
    Vendor
    Dbbroadcast
    Product
    Mozart Next 6000 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Next 7000
    Vendor
    Dbbroadcast
    Product
    Mozart Next 7000 Firmware

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High