Authenticated Root Remote Code Execution through improper filtering of HTTP post request parameters
Vulnerability Description
Authenticated Root Remote Code Execution via improrer user input filtering in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform in main_ok.php user supplied data/hour/time is passed directly into date shell command
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-66259
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Abdul Mhanni
More from DB Electronica Telecomunicazioni S.p.A.
View All →Affected Vendor
DB Electronica Telecomunicazioni S.p.A.
View all reports →