Unauthenticated OS Command Injection (start_upgrade.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform User input passed directly to exec() allows remote code execution via start_upgrade.php. The `/var/tdf/start_upgrade.php` endpoint passes user-controlled `$_GET["filename"]` directly into `exec()` without sanitization or shell escaping. Attackers can inject arbitrary shell commands using metacharacters (`;`, `|`, etc.) to achieve remote code execution as the web server user (likely root).
History

Wed, 03 Dec 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Dbbroadcast mozart Dds Next 100
Dbbroadcast mozart Dds Next 1000
Dbbroadcast mozart Dds Next 1000 Firmware
Dbbroadcast mozart Dds Next 100 Firmware
Dbbroadcast mozart Dds Next 2000
Dbbroadcast mozart Dds Next 2000 Firmware
Dbbroadcast mozart Dds Next 30
Dbbroadcast mozart Dds Next 300
Dbbroadcast mozart Dds Next 3000
Dbbroadcast mozart Dds Next 3000 Firmware
Dbbroadcast mozart Dds Next 300 Firmware
Dbbroadcast mozart Dds Next 30 Firmware
Dbbroadcast mozart Dds Next 3500
Dbbroadcast mozart Dds Next 3500 Firmware
Dbbroadcast mozart Dds Next 50
Dbbroadcast mozart Dds Next 500
Dbbroadcast mozart Dds Next 500 Firmware
Dbbroadcast mozart Dds Next 50 Firmware
Dbbroadcast mozart Dds Next 6000
Dbbroadcast mozart Dds Next 6000 Firmware
Dbbroadcast mozart Dds Next 7000
Dbbroadcast mozart Dds Next 7000 Firmware
Dbbroadcast mozart Next 100
Dbbroadcast mozart Next 1000
Dbbroadcast mozart Next 1000 Firmware
Dbbroadcast mozart Next 100 Firmware
Dbbroadcast mozart Next 2000
Dbbroadcast mozart Next 2000 Firmware
Dbbroadcast mozart Next 30
Dbbroadcast mozart Next 300
Dbbroadcast mozart Next 3000
Dbbroadcast mozart Next 3000 Firmware
Dbbroadcast mozart Next 300 Firmware
Dbbroadcast mozart Next 30 Firmware
Dbbroadcast mozart Next 3500
Dbbroadcast mozart Next 3500 Firmware
Dbbroadcast mozart Next 50
Dbbroadcast mozart Next 500
Dbbroadcast mozart Next 500 Firmware
Dbbroadcast mozart Next 50 Firmware
Dbbroadcast mozart Next 6000
Dbbroadcast mozart Next 6000 Firmware
Dbbroadcast mozart Next 7000
Dbbroadcast mozart Next 7000 Firmware
CPEs cpe:2.3:h:dbbroadcast:mozart_dds_next_1000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_100:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_2000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_3000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_300:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_30:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_3500:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_500:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_50:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_6000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_7000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_1000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_100:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_2000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_3000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_300:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_30:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_3500:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_500:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_50:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_6000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_7000:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_1000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_2000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_3000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_30_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_3500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_50_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_6000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_7000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_1000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_2000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_3000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_30_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_3500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_50_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_6000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_7000_firmware:-:*:*:*:*:*:*:*
Vendors & Products Dbbroadcast mozart Dds Next 100
Dbbroadcast mozart Dds Next 1000
Dbbroadcast mozart Dds Next 1000 Firmware
Dbbroadcast mozart Dds Next 100 Firmware
Dbbroadcast mozart Dds Next 2000
Dbbroadcast mozart Dds Next 2000 Firmware
Dbbroadcast mozart Dds Next 30
Dbbroadcast mozart Dds Next 300
Dbbroadcast mozart Dds Next 3000
Dbbroadcast mozart Dds Next 3000 Firmware
Dbbroadcast mozart Dds Next 300 Firmware
Dbbroadcast mozart Dds Next 30 Firmware
Dbbroadcast mozart Dds Next 3500
Dbbroadcast mozart Dds Next 3500 Firmware
Dbbroadcast mozart Dds Next 50
Dbbroadcast mozart Dds Next 500
Dbbroadcast mozart Dds Next 500 Firmware
Dbbroadcast mozart Dds Next 50 Firmware
Dbbroadcast mozart Dds Next 6000
Dbbroadcast mozart Dds Next 6000 Firmware
Dbbroadcast mozart Dds Next 7000
Dbbroadcast mozart Dds Next 7000 Firmware
Dbbroadcast mozart Next 100
Dbbroadcast mozart Next 1000
Dbbroadcast mozart Next 1000 Firmware
Dbbroadcast mozart Next 100 Firmware
Dbbroadcast mozart Next 2000
Dbbroadcast mozart Next 2000 Firmware
Dbbroadcast mozart Next 30
Dbbroadcast mozart Next 300
Dbbroadcast mozart Next 3000
Dbbroadcast mozart Next 3000 Firmware
Dbbroadcast mozart Next 300 Firmware
Dbbroadcast mozart Next 30 Firmware
Dbbroadcast mozart Next 3500
Dbbroadcast mozart Next 3500 Firmware
Dbbroadcast mozart Next 50
Dbbroadcast mozart Next 500
Dbbroadcast mozart Next 500 Firmware
Dbbroadcast mozart Next 50 Firmware
Dbbroadcast mozart Next 6000
Dbbroadcast mozart Next 6000 Firmware
Dbbroadcast mozart Next 7000
Dbbroadcast mozart Next 7000 Firmware
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 03 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 27 Nov 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Dbbroadcast
Dbbroadcast mozart Fm Transmitter
Vendors & Products Dbbroadcast
Dbbroadcast mozart Fm Transmitter

Wed, 26 Nov 2025 01:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated OS Command Injection (start_upgrade.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform User input passed directly to exec() allows remote code execution via start_upgrade.php. The `/var/tdf/start_upgrade.php` endpoint passes user-controlled `$_GET["filename"]` directly into `exec()` without sanitization or shell escaping. Attackers can inject arbitrary shell commands using metacharacters (`;`, `|`, etc.) to achieve remote code execution as the web server user (likely root).
Title Unauthenticated OS Command Injection (start_upgrade.php)
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 9.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Gridware

Published: 2025-11-26T00:36:29.474Z

Updated: 2025-12-03T15:55:18.897Z

Reserved: 2025-11-26T00:21:33.790Z

Link: CVE-2025-66253

cve-icon Vulnrichment

Updated: 2025-12-03T15:55:15.619Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-26T01:16:08.433

Modified: 2025-12-03T16:47:40.723

Link: CVE-2025-66253

cve-icon Redhat

No data.