Arbitrary File Overwrite via Tar Extraction Path Traversal in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Tar extraction with -C / allow arbitrary file overwrite via crafted archive. The `restore_mozzi_memories.sh` script extracts user-controlled tar archives with `-C /` flag, depositing contents to the filesystem root without path validation. When combined with the unauthenticated file upload vulnerabilities (CVE-01, CVE-06, CVE-07), attackers can craft malicious .tgz archives containing path-traversed filenames (e.g., `etc/shadow`, `var/www/index.php`) to overwrite critical system files in writable directories, achieving full system compromise.
History

Wed, 03 Dec 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Dbbroadcast mozart Dds Next 100
Dbbroadcast mozart Dds Next 1000
Dbbroadcast mozart Dds Next 1000 Firmware
Dbbroadcast mozart Dds Next 100 Firmware
Dbbroadcast mozart Dds Next 2000
Dbbroadcast mozart Dds Next 2000 Firmware
Dbbroadcast mozart Dds Next 30
Dbbroadcast mozart Dds Next 300
Dbbroadcast mozart Dds Next 3000
Dbbroadcast mozart Dds Next 3000 Firmware
Dbbroadcast mozart Dds Next 300 Firmware
Dbbroadcast mozart Dds Next 30 Firmware
Dbbroadcast mozart Dds Next 3500
Dbbroadcast mozart Dds Next 3500 Firmware
Dbbroadcast mozart Dds Next 50
Dbbroadcast mozart Dds Next 500
Dbbroadcast mozart Dds Next 500 Firmware
Dbbroadcast mozart Dds Next 50 Firmware
Dbbroadcast mozart Dds Next 6000
Dbbroadcast mozart Dds Next 6000 Firmware
Dbbroadcast mozart Dds Next 7000
Dbbroadcast mozart Dds Next 7000 Firmware
Dbbroadcast mozart Next 100
Dbbroadcast mozart Next 1000
Dbbroadcast mozart Next 1000 Firmware
Dbbroadcast mozart Next 100 Firmware
Dbbroadcast mozart Next 2000
Dbbroadcast mozart Next 2000 Firmware
Dbbroadcast mozart Next 30
Dbbroadcast mozart Next 300
Dbbroadcast mozart Next 3000
Dbbroadcast mozart Next 3000 Firmware
Dbbroadcast mozart Next 300 Firmware
Dbbroadcast mozart Next 30 Firmware
Dbbroadcast mozart Next 3500
Dbbroadcast mozart Next 3500 Firmware
Dbbroadcast mozart Next 50
Dbbroadcast mozart Next 500
Dbbroadcast mozart Next 500 Firmware
Dbbroadcast mozart Next 50 Firmware
Dbbroadcast mozart Next 6000
Dbbroadcast mozart Next 6000 Firmware
Dbbroadcast mozart Next 7000
Dbbroadcast mozart Next 7000 Firmware
CPEs cpe:2.3:h:dbbroadcast:mozart_dds_next_1000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_100:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_2000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_3000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_300:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_30:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_3500:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_500:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_50:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_6000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_7000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_1000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_100:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_2000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_3000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_300:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_30:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_3500:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_500:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_50:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_6000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_7000:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_1000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_2000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_3000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_30_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_3500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_50_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_6000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_7000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_1000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_2000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_3000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_30_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_3500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_50_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_6000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_7000_firmware:-:*:*:*:*:*:*:*
Vendors & Products Dbbroadcast mozart Dds Next 100
Dbbroadcast mozart Dds Next 1000
Dbbroadcast mozart Dds Next 1000 Firmware
Dbbroadcast mozart Dds Next 100 Firmware
Dbbroadcast mozart Dds Next 2000
Dbbroadcast mozart Dds Next 2000 Firmware
Dbbroadcast mozart Dds Next 30
Dbbroadcast mozart Dds Next 300
Dbbroadcast mozart Dds Next 3000
Dbbroadcast mozart Dds Next 3000 Firmware
Dbbroadcast mozart Dds Next 300 Firmware
Dbbroadcast mozart Dds Next 30 Firmware
Dbbroadcast mozart Dds Next 3500
Dbbroadcast mozart Dds Next 3500 Firmware
Dbbroadcast mozart Dds Next 50
Dbbroadcast mozart Dds Next 500
Dbbroadcast mozart Dds Next 500 Firmware
Dbbroadcast mozart Dds Next 50 Firmware
Dbbroadcast mozart Dds Next 6000
Dbbroadcast mozart Dds Next 6000 Firmware
Dbbroadcast mozart Dds Next 7000
Dbbroadcast mozart Dds Next 7000 Firmware
Dbbroadcast mozart Next 100
Dbbroadcast mozart Next 1000
Dbbroadcast mozart Next 1000 Firmware
Dbbroadcast mozart Next 100 Firmware
Dbbroadcast mozart Next 2000
Dbbroadcast mozart Next 2000 Firmware
Dbbroadcast mozart Next 30
Dbbroadcast mozart Next 300
Dbbroadcast mozart Next 3000
Dbbroadcast mozart Next 3000 Firmware
Dbbroadcast mozart Next 300 Firmware
Dbbroadcast mozart Next 30 Firmware
Dbbroadcast mozart Next 3500
Dbbroadcast mozart Next 3500 Firmware
Dbbroadcast mozart Next 50
Dbbroadcast mozart Next 500
Dbbroadcast mozart Next 500 Firmware
Dbbroadcast mozart Next 50 Firmware
Dbbroadcast mozart Next 6000
Dbbroadcast mozart Next 6000 Firmware
Dbbroadcast mozart Next 7000
Dbbroadcast mozart Next 7000 Firmware
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 27 Nov 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Dbbroadcast
Dbbroadcast mozart Fm Transmitter
Vendors & Products Dbbroadcast
Dbbroadcast mozart Fm Transmitter

Wed, 26 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Nov 2025 01:15:00 +0000

Type Values Removed Values Added
Description Arbitrary File Overwrite via Tar Extraction Path Traversal in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Tar extraction with -C / allow arbitrary file overwrite via crafted archive. The `restore_mozzi_memories.sh` script extracts user-controlled tar archives with `-C /` flag, depositing contents to the filesystem root without path validation. When combined with the unauthenticated file upload vulnerabilities (CVE-01, CVE-06, CVE-07), attackers can craft malicious .tgz archives containing path-traversed filenames (e.g., `etc/shadow`, `var/www/index.php`) to overwrite critical system files in writable directories, achieving full system compromise.
Title Arbitrary File Overwrite via Tar Extraction Path Traversal
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/AU:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Gridware

Published: 2025-11-26T00:50:55.913Z

Updated: 2025-11-26T14:57:11.139Z

Reserved: 2025-11-26T00:21:58.504Z

Link: CVE-2025-66262

cve-icon Vulnrichment

Updated: 2025-11-26T14:56:49.131Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-26T01:16:09.737

Modified: 2025-12-03T16:51:48.860

Link: CVE-2025-66262

cve-icon Redhat

No data.