Unauthenticated Path Traversal with Arbitrary File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform The deletehidden parameter allows path traversal deletion of arbitrary .tgz files.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.abdulmhsblog.com/posts/webfmvulns/ |
|
History
Wed, 26 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Nov 2025 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unauthenticated Path Traversal with Arbitrary File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform The deletehidden parameter allows path traversal deletion of arbitrary .tgz files. | |
| Title | Unauthenticated Path Traversal with Arbitrary File Deletion | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Gridware
Published: 2025-11-26T00:32:26.142Z
Updated: 2025-11-26T15:03:03.656Z
Reserved: 2025-11-26T00:21:33.790Z
Link: CVE-2025-66251
Updated: 2025-11-26T14:58:15.860Z
Status : Received
Published: 2025-11-26T01:16:08.127
Modified: 2025-11-26T01:16:08.127
Link: CVE-2025-66251
No data.