HIGH · 7.2

CVE-2025-63227

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulnerability in the /patch.php endpoint. An attacker with administrative credentials...

Vulnerability Description

The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulnerability in the /patch.php endpoint. An attacker with administrative credentials can upload arbitrary files (e.g., PHP webshells), which are stored in the /patch/ directory. This allows the attacker to execute arbitrary commands on the server, potentially leading to full system compromise.

CVSS Score

7.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DbbroadcastMozart Next 100 Firmware-
DbbroadcastMozart Next 100-
DbbroadcastMozart Next 1000 Firmware-
DbbroadcastMozart Next 1000-
DbbroadcastMozart Next 2000 Firmware-
DbbroadcastMozart Next 2000-
DbbroadcastMozart Next 30 Firmware-
DbbroadcastMozart Next 30-
DbbroadcastMozart Next 300 Firmware-
DbbroadcastMozart Next 300-
DbbroadcastMozart Next 3000 Firmware-
DbbroadcastMozart Next 3000-
DbbroadcastMozart Next 3500 Firmware-
DbbroadcastMozart Next 3500-
DbbroadcastMozart Next 50 Firmware-
DbbroadcastMozart Next 50-
DbbroadcastMozart Next 500 Firmware-
DbbroadcastMozart Next 500-
DbbroadcastMozart Next 6000 Firmware-
DbbroadcastMozart Next 6000-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-63227?

CVE-2025-63227 is a vulnerability with a CVSS score of 7.2 (HIGH). The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulnerability in the /patch.php endpoint. An attacker with administrative credentials...

How severe is CVE-2025-63227?

CVE-2025-63227 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-63227?

Check the references section above for vendor advisories and patch information. Affected products include: Dbbroadcast Mozart Next 100 Firmware, Dbbroadcast Mozart Next 100, Dbbroadcast Mozart Next 1000 Firmware, Dbbroadcast Mozart Next 1000, Dbbroadcast Mozart Next 2000 Firmware.