CVE-2025-66263
中文标题:
(暂无数据)
英文标题:
Unauthenticated Arbitrary File Read via Null Byte Injection
漏洞描述
中文描述:
(暂无数据)
英文描述:
Unauthenticated Arbitrary File Read via Null Byte Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Null byte injection in download_setting.php allows reading arbitrary files. The `/var/tdf/download_setting.php` endpoint constructs file paths by concatenating user-controlled `$_GET['filename']` with a forced `.tgz` extension. Running on PHP 5.3.2 (pre-5.3.4), the application is vulnerable to null byte injection (%00), allowing attackers to bypass the extension restriction and traverse paths. By requesting `filename=../../../../etc/passwd%00`, the underlying C functions treat the null byte as a string terminator, ignoring the appended `.tgz` and enabling unauthenticated arbitrary file disclosure of any file readable by the web server user.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| DB Electronica Telecomunicazioni S.p.A. | Mozart FM Transmitter | 30 | - | - |
cpe:2.3:a:db_electronica_telecomunicazioni_s.p.a.:mozart_fm_transmitter:30:*:*:*:*:*:*:*
|
| DB Electronica Telecomunicazioni S.p.A. | Mozart FM Transmitter | 50 | - | - |
cpe:2.3:a:db_electronica_telecomunicazioni_s.p.a.:mozart_fm_transmitter:50:*:*:*:*:*:*:*
|
| DB Electronica Telecomunicazioni S.p.A. | Mozart FM Transmitter | 100 | - | - |
cpe:2.3:a:db_electronica_telecomunicazioni_s.p.a.:mozart_fm_transmitter:100:*:*:*:*:*:*:*
|
| DB Electronica Telecomunicazioni S.p.A. | Mozart FM Transmitter | 300 | - | - |
cpe:2.3:a:db_electronica_telecomunicazioni_s.p.a.:mozart_fm_transmitter:300:*:*:*:*:*:*:*
|
| DB Electronica Telecomunicazioni S.p.A. | Mozart FM Transmitter | 500 | - | - |
cpe:2.3:a:db_electronica_telecomunicazioni_s.p.a.:mozart_fm_transmitter:500:*:*:*:*:*:*:*
|
| DB Electronica Telecomunicazioni S.p.A. | Mozart FM Transmitter | 1000 | - | - |
cpe:2.3:a:db_electronica_telecomunicazioni_s.p.a.:mozart_fm_transmitter:1000:*:*:*:*:*:*:*
|
| DB Electronica Telecomunicazioni S.p.A. | Mozart FM Transmitter | 2000 | - | - |
cpe:2.3:a:db_electronica_telecomunicazioni_s.p.a.:mozart_fm_transmitter:2000:*:*:*:*:*:*:*
|
| DB Electronica Telecomunicazioni S.p.A. | Mozart FM Transmitter | 3000 | - | - |
cpe:2.3:a:db_electronica_telecomunicazioni_s.p.a.:mozart_fm_transmitter:3000:*:*:*:*:*:*:*
|
| DB Electronica Telecomunicazioni S.p.A. | Mozart FM Transmitter | 3500 | - | - |
cpe:2.3:a:db_electronica_telecomunicazioni_s.p.a.:mozart_fm_transmitter:3500:*:*:*:*:*:*:*
|
| DB Electronica Telecomunicazioni S.p.A. | Mozart FM Transmitter | 6000 | - | - |
cpe:2.3:a:db_electronica_telecomunicazioni_s.p.a.:mozart_fm_transmitter:6000:*:*:*:*:*:*:*
|
| DB Electronica Telecomunicazioni S.p.A. | Mozart FM Transmitter | 7000 | - | - |
cpe:2.3:a:db_electronica_telecomunicazioni_s.p.a.:mozart_fm_transmitter:7000:*:*:*:*:*:*:*
|
| dbbroadcast | mozart_next_3000_firmware | - | - | - |
cpe:2.3:o:dbbroadcast:mozart_next_3000_firmware:-:*:*:*:*:*:*:*
|
| dbbroadcast | mozart_next_3500_firmware | - | - | - |
cpe:2.3:o:dbbroadcast:mozart_next_3500_firmware:-:*:*:*:*:*:*:*
|
| dbbroadcast | mozart_next_50_firmware | - | - | - |
cpe:2.3:o:dbbroadcast:mozart_next_50_firmware:-:*:*:*:*:*:*:*
|
| dbbroadcast | mozart_next_500_firmware | - | - | - |
cpe:2.3:o:dbbroadcast:mozart_next_500_firmware:-:*:*:*:*:*:*:*
|
| dbbroadcast | mozart_next_6000_firmware | - | - | - |
cpe:2.3:o:dbbroadcast:mozart_next_6000_firmware:-:*:*:*:*:*:*:*
|
| dbbroadcast | mozart_next_7000_firmware | - | - | - |
cpe:2.3:o:dbbroadcast:mozart_next_7000_firmware:-:*:*:*:*:*:*:*
|
| dbbroadcast | mozart_next_100_firmware | - | - | - |
cpe:2.3:o:dbbroadcast:mozart_next_100_firmware:-:*:*:*:*:*:*:*
|
| dbbroadcast | mozart_next_1000_firmware | - | - | - |
cpe:2.3:o:dbbroadcast:mozart_next_1000_firmware:-:*:*:*:*:*:*:*
|
| dbbroadcast | mozart_next_2000_firmware | - | - | - |
cpe:2.3:o:dbbroadcast:mozart_next_2000_firmware:-:*:*:*:*:*:*:*
|
| dbbroadcast | mozart_next_30_firmware | - | - | - |
cpe:2.3:o:dbbroadcast:mozart_next_30_firmware:-:*:*:*:*:*:*:*
|
| dbbroadcast | mozart_next_300_firmware | - | - | - |
cpe:2.3:o:dbbroadcast:mozart_next_300_firmware:-:*:*:*:*:*:*:*
|
| dbbroadcast | mozart_dds_next_30_firmware | - | - | - |
cpe:2.3:o:dbbroadcast:mozart_dds_next_30_firmware:-:*:*:*:*:*:*:*
|
| dbbroadcast | mozart_dds_next_50_firmware | - | - | - |
cpe:2.3:o:dbbroadcast:mozart_dds_next_50_firmware:-:*:*:*:*:*:*:*
|
| dbbroadcast | mozart_dds_next_100_firmware | - | - | - |
cpe:2.3:o:dbbroadcast:mozart_dds_next_100_firmware:-:*:*:*:*:*:*:*
|
| dbbroadcast | mozart_dds_next_300_firmware | - | - | - |
cpe:2.3:o:dbbroadcast:mozart_dds_next_300_firmware:-:*:*:*:*:*:*:*
|
| dbbroadcast | mozart_dds_next_500_firmware | - | - | - |
cpe:2.3:o:dbbroadcast:mozart_dds_next_500_firmware:-:*:*:*:*:*:*:*
|
| dbbroadcast | mozart_dds_next_1000_firmware | - | - | - |
cpe:2.3:o:dbbroadcast:mozart_dds_next_1000_firmware:-:*:*:*:*:*:*:*
|
| dbbroadcast | mozart_dds_next_2000_firmware | - | - | - |
cpe:2.3:o:dbbroadcast:mozart_dds_next_2000_firmware:-:*:*:*:*:*:*:*
|
| dbbroadcast | mozart_dds_next_3000_firmware | - | - | - |
cpe:2.3:o:dbbroadcast:mozart_dds_next_3000_firmware:-:*:*:*:*:*:*:*
|
| dbbroadcast | mozart_dds_next_3500_firmware | - | - | - |
cpe:2.3:o:dbbroadcast:mozart_dds_next_3500_firmware:-:*:*:*:*:*:*:*
|
| dbbroadcast | mozart_dds_next_6000_firmware | - | - | - |
cpe:2.3:o:dbbroadcast:mozart_dds_next_6000_firmware:-:*:*:*:*:*:*:*
|
| dbbroadcast | mozart_dds_next_7000_firmware | - | - | - |
cpe:2.3:o:dbbroadcast:mozart_dds_next_7000_firmware:-:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
4.0 (cna)
HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-66263 |
2025-11-27 03:28:08 | 2026-01-12 02:12:24 |
| NVD | nvd_CVE-2025-66263 |
2025-12-04 03:00:02 | 2026-01-12 02:28:03 |
版本与语言
安全公告
变更历史
查看详细变更
- affected_products_count: 11 -> 33
- data_sources: ['cve'] -> ['cve', 'nvd']