CVE-2025-66253 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Unauthenticated OS Command Injection (start_upgrade.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000,…
Critical CVSS: 9.9

CVE-2025-66253

Unauthenticated OS Command Injection (start_upgrade.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform User input passed directly to exec() allows remote code execution via start_upgrade.php. The `/var/tdf/start_upgrade.php` endpoint passes user-controlled `$_GET["filename"]` directly into `exec()` without sanitization or shell escaping. Attackers can inject arbitrary shell commands using metacharacters (`;`, `|`, etc.) to achieve remote code execution as the web server user (likely root).
Vendor
Dbbroadcast
Product
Mozart Next 100 Firmware
CWE
CWE-78
Yayın Tarihi
2025-11-26 01:16:08
Güncelleme
2025-12-03 16:47:40
Source Identifier
b7efe717-a805-47cf-8e9a-921fca0ce0ce
KEV Date Added
-

Kategoriler

Referanslar