CVE Feed

    Dashboard / CVE / CVE-2025-66263

    CVE-2025-66263

    Unauthenticated Arbitrary File Read via Null Byte Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Null byte injection in download_setting.php allows reading arbitrary files. The `/var/tdf/download_setting.php` endpoint constructs file paths by concatenating user-controlled `$_GET['filename']` with a forced `.tgz` extension. Running on PHP 5.3.2 (pre-5.3.4), the application is vulnerable to null byte injection (%00), allowing attackers to bypass the extension restriction and traverse paths. By requesting `filename=../../../../etc/passwd%00`, the underlying C functions treat the null byte as a string terminator, ignoring the appended `.tgz` and enabling unauthenticated arbitrary file disclosure of any file readable by the web server user.

    Published:Nov 26, 2025
    Last Modified:Dec 3, 2025
    EPS:Nov 26, 2025
    EPSS Score:0.00055
    CVSS Score:7.5

    Affected Products

    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 100
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 1000
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 1000 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 100 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 2000
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 2000 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 30
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 300
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 3000
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 3000 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 300 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 30 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 3500
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 3500 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 50
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 500
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 500 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 50 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 6000
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 6000 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 7000
    Vendor
    Dbbroadcast
    Product
    Mozart Dds Next 7000 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Fm Transmitter
    Vendor
    Dbbroadcast
    Product
    Mozart Next 100
    Vendor
    Dbbroadcast
    Product
    Mozart Next 1000
    Vendor
    Dbbroadcast
    Product
    Mozart Next 1000 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Next 100 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Next 2000
    Vendor
    Dbbroadcast
    Product
    Mozart Next 2000 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Next 30
    Vendor
    Dbbroadcast
    Product
    Mozart Next 300
    Vendor
    Dbbroadcast
    Product
    Mozart Next 3000
    Vendor
    Dbbroadcast
    Product
    Mozart Next 3000 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Next 300 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Next 30 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Next 3500
    Vendor
    Dbbroadcast
    Product
    Mozart Next 3500 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Next 50
    Vendor
    Dbbroadcast
    Product
    Mozart Next 500
    Vendor
    Dbbroadcast
    Product
    Mozart Next 500 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Next 50 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Next 6000
    Vendor
    Dbbroadcast
    Product
    Mozart Next 6000 Firmware
    Vendor
    Dbbroadcast
    Product
    Mozart Next 7000
    Vendor
    Dbbroadcast
    Product
    Mozart Next 7000 Firmware

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High