The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulnerability in the /patch.php endpoint. An attacker with administrative credentials can upload arbitrary files (e.g., PHP webshells), which are stored in the /patch/ directory. This allows the attacker to execute arbitrary commands on the server, potentially leading to full system compromise.
History

Mon, 08 Dec 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Dbbroadcast mozart Dds Next 100
Dbbroadcast mozart Dds Next 1000
Dbbroadcast mozart Dds Next 1000 Firmware
Dbbroadcast mozart Dds Next 100 Firmware
Dbbroadcast mozart Dds Next 2000
Dbbroadcast mozart Dds Next 2000 Firmware
Dbbroadcast mozart Dds Next 30
Dbbroadcast mozart Dds Next 300
Dbbroadcast mozart Dds Next 3000
Dbbroadcast mozart Dds Next 3000 Firmware
Dbbroadcast mozart Dds Next 300 Firmware
Dbbroadcast mozart Dds Next 30 Firmware
Dbbroadcast mozart Dds Next 3500
Dbbroadcast mozart Dds Next 3500 Firmware
Dbbroadcast mozart Dds Next 50
Dbbroadcast mozart Dds Next 500
Dbbroadcast mozart Dds Next 500 Firmware
Dbbroadcast mozart Dds Next 50 Firmware
Dbbroadcast mozart Dds Next 6000
Dbbroadcast mozart Dds Next 6000 Firmware
Dbbroadcast mozart Dds Next 7000
Dbbroadcast mozart Dds Next 7000 Firmware
Dbbroadcast mozart Next 100
Dbbroadcast mozart Next 1000
Dbbroadcast mozart Next 1000 Firmware
Dbbroadcast mozart Next 100 Firmware
Dbbroadcast mozart Next 2000
Dbbroadcast mozart Next 2000 Firmware
Dbbroadcast mozart Next 30
Dbbroadcast mozart Next 300
Dbbroadcast mozart Next 3000
Dbbroadcast mozart Next 3000 Firmware
Dbbroadcast mozart Next 300 Firmware
Dbbroadcast mozart Next 30 Firmware
Dbbroadcast mozart Next 3500
Dbbroadcast mozart Next 3500 Firmware
Dbbroadcast mozart Next 50
Dbbroadcast mozart Next 500
Dbbroadcast mozart Next 500 Firmware
Dbbroadcast mozart Next 50 Firmware
Dbbroadcast mozart Next 6000
Dbbroadcast mozart Next 6000 Firmware
Dbbroadcast mozart Next 7000
Dbbroadcast mozart Next 7000 Firmware
CPEs cpe:2.3:h:dbbroadcast:mozart_dds_next_1000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_100:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_2000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_3000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_300:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_30:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_3500:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_500:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_50:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_6000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_7000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_1000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_100:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_2000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_3000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_300:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_30:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_3500:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_500:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_50:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_6000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_7000:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_1000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_2000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_3000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_30_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_3500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_50_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_6000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_7000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_1000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_2000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_3000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_30_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_3500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_50_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_6000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_7000_firmware:-:*:*:*:*:*:*:*
Vendors & Products Dbbroadcast mozart Dds Next 100
Dbbroadcast mozart Dds Next 1000
Dbbroadcast mozart Dds Next 1000 Firmware
Dbbroadcast mozart Dds Next 100 Firmware
Dbbroadcast mozart Dds Next 2000
Dbbroadcast mozart Dds Next 2000 Firmware
Dbbroadcast mozart Dds Next 30
Dbbroadcast mozart Dds Next 300
Dbbroadcast mozart Dds Next 3000
Dbbroadcast mozart Dds Next 3000 Firmware
Dbbroadcast mozart Dds Next 300 Firmware
Dbbroadcast mozart Dds Next 30 Firmware
Dbbroadcast mozart Dds Next 3500
Dbbroadcast mozart Dds Next 3500 Firmware
Dbbroadcast mozart Dds Next 50
Dbbroadcast mozart Dds Next 500
Dbbroadcast mozart Dds Next 500 Firmware
Dbbroadcast mozart Dds Next 50 Firmware
Dbbroadcast mozart Dds Next 6000
Dbbroadcast mozart Dds Next 6000 Firmware
Dbbroadcast mozart Dds Next 7000
Dbbroadcast mozart Dds Next 7000 Firmware
Dbbroadcast mozart Next 100
Dbbroadcast mozart Next 1000
Dbbroadcast mozart Next 1000 Firmware
Dbbroadcast mozart Next 100 Firmware
Dbbroadcast mozart Next 2000
Dbbroadcast mozart Next 2000 Firmware
Dbbroadcast mozart Next 30
Dbbroadcast mozart Next 300
Dbbroadcast mozart Next 3000
Dbbroadcast mozart Next 3000 Firmware
Dbbroadcast mozart Next 300 Firmware
Dbbroadcast mozart Next 30 Firmware
Dbbroadcast mozart Next 3500
Dbbroadcast mozart Next 3500 Firmware
Dbbroadcast mozart Next 50
Dbbroadcast mozart Next 500
Dbbroadcast mozart Next 500 Firmware
Dbbroadcast mozart Next 50 Firmware
Dbbroadcast mozart Next 6000
Dbbroadcast mozart Next 6000 Firmware
Dbbroadcast mozart Next 7000
Dbbroadcast mozart Next 7000 Firmware

Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Dbbroadcast
Dbbroadcast mozart Fm Transmitter
Vendors & Products Dbbroadcast
Dbbroadcast mozart Fm Transmitter

Wed, 19 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-434
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Nov 2025 19:45:00 +0000

Type Values Removed Values Added
Description The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulnerability in the /patch.php endpoint. An attacker with administrative credentials can upload arbitrary files (e.g., PHP webshells), which are stored in the /patch/ directory. This allows the attacker to execute arbitrary commands on the server, potentially leading to full system compromise.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-11-18T00:00:00.000Z

Updated: 2025-11-19T15:46:24.479Z

Reserved: 2025-10-27T00:00:00.000Z

Link: CVE-2025-63227

cve-icon Vulnrichment

Updated: 2025-11-19T15:46:15.185Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-18T20:15:47.817

Modified: 2025-12-08T14:43:49.970

Link: CVE-2025-63227

cve-icon Redhat

No data.