CVE-2025-66263
HIGHDescription
Unauthenticated Arbitrary File Read via Null Byte Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Null byte injection in download_setting.php allows reading arbitrary files. The `/var/tdf/download_setting.php` endpoint constructs file paths by concatenating user-controlled `$_GET['filename']` with a forced `.tgz` extension. Running on PHP 5.3.2 (pre-5.3.4), the application is vulnerable to null byte injection (%00), allowing attackers to bypass the extension restriction and traverse paths. By requesting `filename=../../../../etc/passwd%00`, the underlying C functions treat the null byte as a string terminator, ignoring the appended `.tgz` and enabling unauthenticated arbitrary file disclosure of any file readable by the web server user.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| dbbroadcast | mozart_next_3000_firmware |
| dbbroadcast | mozart_next_3000 |
| dbbroadcast | mozart_next_3500_firmware |
| dbbroadcast | mozart_next_3500 |
| dbbroadcast | mozart_next_50_firmware |
| dbbroadcast | mozart_next_50 |
| dbbroadcast | mozart_next_500_firmware |
| dbbroadcast | mozart_next_500 |
| dbbroadcast | mozart_next_6000_firmware |
| dbbroadcast | mozart_next_6000 |
| dbbroadcast | mozart_next_7000_firmware |
| dbbroadcast | mozart_next_7000 |
| dbbroadcast | mozart_next_100_firmware |
| dbbroadcast | mozart_next_100 |
| dbbroadcast | mozart_next_1000_firmware |
| dbbroadcast | mozart_next_1000 |
| dbbroadcast | mozart_next_2000_firmware |
| dbbroadcast | mozart_next_2000 |
| dbbroadcast | mozart_next_30_firmware |
| dbbroadcast | mozart_next_30 |
| dbbroadcast | mozart_next_300_firmware |
| dbbroadcast | mozart_next_300 |
| dbbroadcast | mozart_dds_next_30_firmware |
| dbbroadcast | mozart_dds_next_30 |
| dbbroadcast | mozart_dds_next_50_firmware |
| dbbroadcast | mozart_dds_next_50 |
| dbbroadcast | mozart_dds_next_100_firmware |
| dbbroadcast | mozart_dds_next_100 |
| dbbroadcast | mozart_dds_next_300_firmware |
| dbbroadcast | mozart_dds_next_300 |
| dbbroadcast | mozart_dds_next_500_firmware |
| dbbroadcast | mozart_dds_next_500 |
| dbbroadcast | mozart_dds_next_1000_firmware |
| dbbroadcast | mozart_dds_next_1000 |
| dbbroadcast | mozart_dds_next_2000_firmware |
| dbbroadcast | mozart_dds_next_2000 |
| dbbroadcast | mozart_dds_next_3000_firmware |
| dbbroadcast | mozart_dds_next_3000 |
| dbbroadcast | mozart_dds_next_3500_firmware |
| dbbroadcast | mozart_dds_next_3500 |
| dbbroadcast | mozart_dds_next_6000_firmware |
| dbbroadcast | mozart_dds_next_6000 |
| dbbroadcast | mozart_dds_next_7000_firmware |
| dbbroadcast | mozart_dds_next_7000 |
References
Frequently Asked Questions
What is CVE-2025-66263? +
How severe is CVE-2025-66263? +
What products are affected by CVE-2025-66263? +
How do I check if I'm vulnerable to CVE-2025-66263? +
Related Vulnerabilities
A vulnerability in the CivetWeb library's function mg_handle_form_request allows remote attackers to trigger a denial of service (DoS) condition. By …
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary …
The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all versions up …
If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support …
jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when …
An authorized user may trigger crashes or receive the contents of buffer over-reads of Server memory by issuing specially crafted …