CVE-2025-66262

Arbitrary File Overwrite via Tar Extraction Path Traversal in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Tar extraction with -C / allow arbitrary file overwrite via crafted archive. The `restore_mozzi_memories.sh` script extracts user-controlled tar archives with `-C /` flag, depositing contents to the filesystem root without path validation. When combined with the unauthenticated file upload vulnerabilities (CVE-01, CVE-06, CVE-07), attackers can craft malicious .tgz archives containing path-traversed filenames (e.g., `etc/shadow`, `var/www/index.php`) to overwrite critical system files in writable directories, achieving full system compromise.
References
Link Resource
https://www.abdulmhsblog.com/posts/webfmvulns/ Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_100:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_1000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_1000:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_2000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_2000:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_30_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_30:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_300:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_3000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_3000:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_3500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_3500:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_50_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_50:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_500:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_6000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_6000:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_next_7000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_7000:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_30_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_30:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_50_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_50:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_100:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_300:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_500:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_1000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_1000:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_2000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_2000:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_3000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_3000:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_3500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_3500:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_6000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_6000:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:dbbroadcast:mozart_dds_next_7000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_7000:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-11-26 01:16

Updated : 2025-12-03 16:51


NVD link : CVE-2025-66262

Mitre link : CVE-2025-66262

CVE.ORG link : CVE-2025-66262


JSON object : View

Products Affected

dbbroadcast

  • mozart_next_7000
  • mozart_dds_next_50_firmware
  • mozart_dds_next_2000_firmware
  • mozart_dds_next_1000_firmware
  • mozart_dds_next_500
  • mozart_next_3500
  • mozart_next_1000
  • mozart_next_6000_firmware
  • mozart_next_3000_firmware
  • mozart_next_100
  • mozart_next_7000_firmware
  • mozart_dds_next_30_firmware
  • mozart_dds_next_6000
  • mozart_next_6000
  • mozart_dds_next_300_firmware
  • mozart_next_3500_firmware
  • mozart_dds_next_6000_firmware
  • mozart_next_100_firmware
  • mozart_next_300_firmware
  • mozart_next_2000
  • mozart_dds_next_3000
  • mozart_next_500_firmware
  • mozart_dds_next_3500_firmware
  • mozart_dds_next_300
  • mozart_next_3000
  • mozart_dds_next_3500
  • mozart_dds_next_2000
  • mozart_next_500
  • mozart_dds_next_3000_firmware
  • mozart_dds_next_100_firmware
  • mozart_next_30_firmware
  • mozart_next_50
  • mozart_dds_next_7000
  • mozart_next_1000_firmware
  • mozart_dds_next_7000_firmware
  • mozart_next_2000_firmware
  • mozart_dds_next_100
  • mozart_dds_next_1000
  • mozart_dds_next_30
  • mozart_next_300
  • mozart_dds_next_50
  • mozart_next_50_firmware
  • mozart_dds_next_500_firmware
  • mozart_next_30
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')