Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 31 Dec 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sourcefabric
Sourcefabric phoniebox |
|
| CPEs | cpe:2.3:a:sourcefabric:phoniebox:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sourcefabric
Sourcefabric phoniebox |
Sun, 21 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Miczflor
Miczflor rpi-jukebox-rfid |
|
| Vendors & Products |
Miczflor
Miczflor rpi-jukebox-rfid |
Thu, 18 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-502 | |
| Metrics |
cvssV3_1
|
Thu, 18 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An insecure deserialization vulnerability exists in the rss-mp3.php script of the MiczFlor RPi-Jukebox-RFID project through commit 4b2334f0ae0e87c0568876fc41c48c38aa9a7014 (2025-10-07). The 'rss' GET parameter receives data that is passed directly to the unserialize() function without validation. This allows a remote, unauthenticated attacker to inject arbitrary PHP objects, causing the application to process them and leading to errors or a denial of service. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-18T21:17:52.996Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63951
Updated: 2025-12-18T21:16:38.171Z
Status : Analyzed
Published: 2025-12-18T21:15:55.070
Modified: 2025-12-31T19:27:41.563
Link: CVE-2025-63951
No data.
OpenCVE Enrichment
Updated: 2025-12-21T21:15:01Z