DB Electronica Mozart FM Transmitter是意大利DB Electronica公司的一个专业级FM广播发射机系列。 DB Electronica Mozart FM Transmitter 30版本、50版本、100版本、300版本、500版本、1000版本、2000版本、3000版本、3500版本、6000版本和7000版本存在安全漏洞,该漏洞源于status_contents.php中unlink失败导致无限循环,可能导致拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| DB Electronica Telecomunicazioni S.p.A. | Mozart FM Transmitter | 30 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-66257 | Unauthenticated Arbitrary File Deletion (patch_contents.php) | |
| CVE-2025-66256 | Unauthenticated Arbitrary File Upload (patch_contents.php) | |
| CVE-2025-66255 | Unauthenticated Arbitrary File Upload (upgrade_contents.php) | |
| CVE-2025-66253 | Unauthenticated OS Command Injection (start_upgrade.php) | |
| CVE-2025-66254 | Unauthenticated Arbitrary File Deletion (upgrade_contents.php) | |
| CVE-2025-66250 | Unauthenticated Arbitrary File Upload (status_contents.php) | |
| CVE-2025-66251 | Unauthenticated Path Traversal with Arbitrary File Deletion | |
| CVE-2025-66262 | Arbitrary File Overwrite via Tar Extraction Path Traversal | |
| CVE-2025-66259 | Authenticated Root Remote Code Execution through improper filtering of HTTP post request p | |
| CVE-2025-66263 | Unauthenticated Arbitrary File Read via Null Byte Injection | |
| CVE-2025-66258 | Stored Cross-Site Scripting via XML Injection | |
| CVE-2025-66260 | PostgreSQL SQL Injection (status_sql.php) | |
| CVE-2025-66261 | Unauthenticated OS Command Injection (restore_settings.php) |
No comments yet