V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2025-66263
CVE
High

Unauthenticated Arbitrary File Read via Null Byte Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 5…

CVSS
8.9
High
EPSS
0.00
p24
Published
2025-01-01
Updated
2025-01-01
Description

Unauthenticated Arbitrary File Read via Null Byte Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Null byte injection in download_setting.php allows reading arbitrary files. The `/var/tdf/download_setting.php` endpoint constructs file paths by concatenating user-controlled `$_GET['filename']` with a forced `.tgz` extension. Running on PHP 5.3.2 (pre-5.3.4), the application is vulnerable to null byte injection (%00), allowing attackers to bypass the extension restriction and traverse paths. By requesting `filename=../../../../etc/passwd%00`, the underlying C functions treat the null byte as a string terminator, ignoring the appended `.tgz` and enabling unauthenticated arbitrary file disclosure of any file readable by the web server user.

Tags · CWE
Pre-auth
CWE-158
CAPEC-52
CAPEC-53
Affected products
Mozart_dds_next_1000_firmwareMozart_dds_next_100_firmwareMozart_dds_next_2000_firmwareMozart_dds_next_3000_firmwareMozart_dds_next_300_firmwareMozart_dds_next_30_firmwareMozart_dds_next_3500_firmwareMozart_dds_next_500_firmwareMozart_dds_next_50_firmwareMozart_dds_next_6000_firmwareMozart_dds_next_7000_firmwareMozart_next_1000_firmwareMozart_next_100_firmwareMozart_next_2000_firmwareMozart_next_3000_firmwareMozart_next_300_firmwareMozart_next_30_firmwareMozart_next_3500_firmwareMozart_next_500_firmwareMozart_next_50_firmware
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Timeline
2025-01-01
Published
2025-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Attack Requirements
AT: P
Present
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Vulnerable System Confidentiality
VC: H
High (H)
Vulnerable System Integrity
VI: N
None (N)
Vulnerable System Availability
VA: N
None (N)
Subsequent System Confidentiality
SC: H
High (H)
Subsequent System Integrity
SI: N
None (N)
Subsequent System Availability
SA: N
None (N)
Exploit Code Maturity
E: X
Not Defined
Confidentiality Requirement
CR: X
Not Defined
Integrity Requirement
IR: X
Not Defined
Availability Requirement
AR: X
Not Defined
Modified Attack Vector
MAV: X
Not Defined
Modified Attack Complexity
MAC: X
Not Defined
Modified Attack Requirements
MAT: X
Not Defined
Modified Privileges Required
MPR: X
Not Defined
Modified User Interaction
MUI: X
Not Defined
Modified Vulnerable System Confidentiality
MVC: X
Not Defined
Modified Vulnerable System Integrity
MVI: X
Not Defined
Modified Vulnerable System Availability
MVA: X
Not Defined
Modified Subsequent System Confidentiality
MSC: X
Not Defined
Modified Subsequent System Integrity
MSI: X
Not Defined
Modified Subsequent System Availability
MSA: X
Not Defined
s
S: X
X
au
AU: X
X
r
R: X
X
v
V: X
X
re
RE: X
X
u
U: X
X
Exploit indicators
EPSS
0.003 · p24
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
mozart_dds_next_1000_firmware*Tracked
mozart_dds_next_100_firmware*Tracked
mozart_dds_next_2000_firmware*Tracked
mozart_dds_next_3000_firmware*Tracked
mozart_dds_next_300_firmware*Tracked
mozart_dds_next_30_firmware*Tracked
mozart_dds_next_3500_firmware*Tracked
mozart_dds_next_500_firmware*Tracked
mozart_dds_next_50_firmware*Tracked
mozart_dds_next_6000_firmware*Tracked
mozart_dds_next_7000_firmware*Tracked
mozart_next_1000_firmware*Tracked
mozart_next_100_firmware*Tracked
mozart_next_2000_firmware*Tracked
mozart_next_3000_firmware*Tracked
mozart_next_300_firmware*Tracked
mozart_next_30_firmware*Tracked
mozart_next_3500_firmware*Tracked
mozart_next_500_firmware*Tracked
mozart_next_50_firmware*Tracked
Showing first 20 of 22
Source databases
CVE