Overview
- DB Electronica Telecomunicazioni S.p.A.
- Mozart FM Transmitter
Description
Statistics
- 2 Posts
- 8 Interactions
Fediverse
🚨 CVE-2025-66257 (CRITICAL, CVSS 9.2): Mozart FM Transmitters (DB Electronica) allow unauthenticated file deletion via patch_contents.php. Segment networks, monitor traffic, restrict access—patch pending! More: https://radar.offseq.com/threat/cve-2025-66257-cwe-73-unauthenticated-arbitrary-fi-71769393 #OffSeq #Infosec #CVE202566257 #BroadcastSecurity
Go hack more radio shit.
https://www.abdulmhsblog.com/posts/webfmvulns/
- CVE-2025-66259: Authenticated Root RCE (main_ok.php)
- CVE-2025-66253: Unauthenticated OS Command Injection (Upgrade)
- CVE-2025-66261: Unauthenticated OS Command Injection (Restore)
- CVE-2025-66262: Arbitrary File Overwrite (Tar Path Traversal)
- CVE-2025-66250: Unrestricted File Upload (Status)
- CVE-2025-66255: Unsigned Firmware Upload
- CVE-2025-66256: Unrestricted Patch Upload
- CVE-2025-66251: Path Traversal File Deletion
- CVE-2025-66254: Arbitrary File Deletion (Upgrade)
- CVE-2025-66263: Arbitrary File Read (Null Byte Injection)
- CVE-2025-66260: SQL Injection
- CVE-2025-66258: Stored XSS via XML Injection
- CVE-2025-66257: Arbitrary Patch Deletion
- CVE-2025-66252: Infinite Loop Denial of Service
Overview
- DB Electronica Telecomunicazioni S.p.A.
- Mozart FM Transmitter
Description
Statistics
- 2 Posts
- 8 Interactions
Fediverse
🚨 CRITICAL (CVSS 9.9): DB Electronica Mozart FM Transmitters (30–7000) vulnerable to unauthenticated OS command injection (CVE-2025-66261) via restore_settings.php. Restrict access, enable WAF/IDS, and monitor now! https://radar.offseq.com/threat/cve-2025-66261-cwe-78-unauthenticated-os-command-i-e3fa977a #OffSeq #CVE202566261 #RCE #BroadcastSec
Go hack more radio shit.
https://www.abdulmhsblog.com/posts/webfmvulns/
- CVE-2025-66259: Authenticated Root RCE (main_ok.php)
- CVE-2025-66253: Unauthenticated OS Command Injection (Upgrade)
- CVE-2025-66261: Unauthenticated OS Command Injection (Restore)
- CVE-2025-66262: Arbitrary File Overwrite (Tar Path Traversal)
- CVE-2025-66250: Unrestricted File Upload (Status)
- CVE-2025-66255: Unsigned Firmware Upload
- CVE-2025-66256: Unrestricted Patch Upload
- CVE-2025-66251: Path Traversal File Deletion
- CVE-2025-66254: Arbitrary File Deletion (Upgrade)
- CVE-2025-66263: Arbitrary File Read (Null Byte Injection)
- CVE-2025-66260: SQL Injection
- CVE-2025-66258: Stored XSS via XML Injection
- CVE-2025-66257: Arbitrary Patch Deletion
- CVE-2025-66252: Infinite Loop Denial of Service
Overview
- DB Electronica Telecomunicazioni S.p.A.
- Mozart FM Transmitter
Description
Statistics
- 2 Posts
- 8 Interactions
Fediverse
🚨 CRITICAL: CVE-2025-66259 hits DB Mozart FM Transmitters (v30-7000) — improper input validation lets authenticated root users execute remote code. Broadcast ops at risk — restrict access & monitor for RCE. https://radar.offseq.com/threat/cve-2025-66259-cwe-20-improper-input-validation-in-9a138e69 #OffSeq #CVE202566259 #security #RCE
Go hack more radio shit.
https://www.abdulmhsblog.com/posts/webfmvulns/
- CVE-2025-66259: Authenticated Root RCE (main_ok.php)
- CVE-2025-66253: Unauthenticated OS Command Injection (Upgrade)
- CVE-2025-66261: Unauthenticated OS Command Injection (Restore)
- CVE-2025-66262: Arbitrary File Overwrite (Tar Path Traversal)
- CVE-2025-66250: Unrestricted File Upload (Status)
- CVE-2025-66255: Unsigned Firmware Upload
- CVE-2025-66256: Unrestricted Patch Upload
- CVE-2025-66251: Path Traversal File Deletion
- CVE-2025-66254: Arbitrary File Deletion (Upgrade)
- CVE-2025-66263: Arbitrary File Read (Null Byte Injection)
- CVE-2025-66260: SQL Injection
- CVE-2025-66258: Stored XSS via XML Injection
- CVE-2025-66257: Arbitrary Patch Deletion
- CVE-2025-66252: Infinite Loop Denial of Service
Overview
- DB Electronica Telecomunicazioni S.p.A.
- Mozart FM Transmitter
Description
Statistics
- 2 Posts
- 8 Interactions
Fediverse
🚨 CVE-2025-66262 (CRITICAL): Mozart FM Transmitters (v30–7000) vulnerable to arbitrary file overwrite via tar extraction path traversal in restore_mozzi_memories.sh. Attackers can fully compromise devices. Patch & restrict uploads! https://radar.offseq.com/threat/cve-2025-66262-cwe-22-arbitrary-file-overwrite-via-a79c9cf2 #OffSeq #CVE202566262 #Infosec
Go hack more radio shit.
https://www.abdulmhsblog.com/posts/webfmvulns/
- CVE-2025-66259: Authenticated Root RCE (main_ok.php)
- CVE-2025-66253: Unauthenticated OS Command Injection (Upgrade)
- CVE-2025-66261: Unauthenticated OS Command Injection (Restore)
- CVE-2025-66262: Arbitrary File Overwrite (Tar Path Traversal)
- CVE-2025-66250: Unrestricted File Upload (Status)
- CVE-2025-66255: Unsigned Firmware Upload
- CVE-2025-66256: Unrestricted Patch Upload
- CVE-2025-66251: Path Traversal File Deletion
- CVE-2025-66254: Arbitrary File Deletion (Upgrade)
- CVE-2025-66263: Arbitrary File Read (Null Byte Injection)
- CVE-2025-66260: SQL Injection
- CVE-2025-66258: Stored XSS via XML Injection
- CVE-2025-66257: Arbitrary Patch Deletion
- CVE-2025-66252: Infinite Loop Denial of Service
Overview
- DB Electronica Telecomunicazioni S.p.A.
- Mozart FM Transmitter
Description
Statistics
- 2 Posts
- 8 Interactions
Fediverse
Go hack more radio shit.
https://www.abdulmhsblog.com/posts/webfmvulns/
- CVE-2025-66259: Authenticated Root RCE (main_ok.php)
- CVE-2025-66253: Unauthenticated OS Command Injection (Upgrade)
- CVE-2025-66261: Unauthenticated OS Command Injection (Restore)
- CVE-2025-66262: Arbitrary File Overwrite (Tar Path Traversal)
- CVE-2025-66250: Unrestricted File Upload (Status)
- CVE-2025-66255: Unsigned Firmware Upload
- CVE-2025-66256: Unrestricted Patch Upload
- CVE-2025-66251: Path Traversal File Deletion
- CVE-2025-66254: Arbitrary File Deletion (Upgrade)
- CVE-2025-66263: Arbitrary File Read (Null Byte Injection)
- CVE-2025-66260: SQL Injection
- CVE-2025-66258: Stored XSS via XML Injection
- CVE-2025-66257: Arbitrary Patch Deletion
- CVE-2025-66252: Infinite Loop Denial of Service
Overview
- Microsoft
- Visual Studio Code
Description
Statistics
- 1 Post
- 1 Interaction
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- Grafana
- Grafana Enterprise
Description
Statistics
- 1 Post
- 1 Interaction
Bluesky
Overview
Description
Statistics
- 1 Post
Overview
- Zenitel
- TCIV-3+
Description
Statistics
- 1 Post
Fediverse
📰 CISA Warns of Critical Flaws in Industrial Control Systems, Including CVSS 10.0 Bug
🚨 CISA releases 7 ICS advisories for flaws in Rockwell, Zenitel & other OT gear. A critical CVSS 10.0 RCE vulnerability (CVE-2025-64130) affects Zenitel comms equipment. Asset owners urged to patch immediately. #ICS #OTsecurity #Vulnerability #CISA