CVE-2025-63229

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains a reflected Cross-Site Scripting (XSS) vulnerability in the /main0.php endpoint. By injecting a malicious JavaScript payload into the ?m= query parameter, an attacker can execute arbitrary code in the victim's browser, potentially stealing sensitive information, hijacking sessions, or performing unauthorized actions.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_100:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_1000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_1000:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_2000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_2000:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_30_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_30:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_300:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_3000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_3000:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_3500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_3500:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_50_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_50:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_500:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_6000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_6000:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_7000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_7000:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_30_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_30:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_50_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_50:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_100:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_300:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_500:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_1000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_1000:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_2000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_2000:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_3000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_3000:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_3500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_3500:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_6000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_6000:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_7000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_7000:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-11-18 22:15

Updated : 2025-12-06 00:18


NVD link : CVE-2025-63229

Mitre link : CVE-2025-63229

CVE.ORG link : CVE-2025-63229


JSON object : View

Products Affected

dbbroadcast

  • mozart_next_7000
  • mozart_dds_next_50_firmware
  • mozart_dds_next_2000_firmware
  • mozart_dds_next_1000_firmware
  • mozart_dds_next_500
  • mozart_next_3500
  • mozart_next_1000
  • mozart_next_6000_firmware
  • mozart_next_3000_firmware
  • mozart_next_100
  • mozart_next_7000_firmware
  • mozart_dds_next_30_firmware
  • mozart_dds_next_6000
  • mozart_next_6000
  • mozart_dds_next_300_firmware
  • mozart_next_3500_firmware
  • mozart_dds_next_6000_firmware
  • mozart_next_100_firmware
  • mozart_next_300_firmware
  • mozart_next_2000
  • mozart_dds_next_3000
  • mozart_next_500_firmware
  • mozart_dds_next_3500_firmware
  • mozart_dds_next_300
  • mozart_next_3000
  • mozart_dds_next_3500
  • mozart_dds_next_2000
  • mozart_next_500
  • mozart_dds_next_3000_firmware
  • mozart_dds_next_100_firmware
  • mozart_next_30_firmware
  • mozart_next_50
  • mozart_dds_next_7000
  • mozart_next_1000_firmware
  • mozart_dds_next_7000_firmware
  • mozart_next_2000_firmware
  • mozart_dds_next_100
  • mozart_dds_next_1000
  • mozart_dds_next_30
  • mozart_next_300
  • mozart_dds_next_50
  • mozart_next_50_firmware
  • mozart_dds_next_500_firmware
  • mozart_next_30
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')