Vulnerabilities
CVE-2025-66253 - Unauthenticated OS Command Injection (start_upgrade.php)
CVE ID : CVE-2025-66253 Published : Nov. 26, 2025, 12:36 a.m. | 26 minutes ago Description : Unauthenticated OS Command Injection (start_upgrade.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform User input passed directly to exec() allows remote code execution via start_upgrade.php. The `/var/tdf/start_upgrade.php` endpoint passes user-controlled `$_GET[
CVE Details
CVE ID
Published
Nov. 26, 2025
Affected Product:
php
Impact:
Command Injection
Source: Telegram CVE Monitor