An insecure deserialization vulnerability exists in the rss-mp3.php script of the MiczFlor RPi-Jukebox-RFID project through commit 4b2334f0ae0e87c0568876fc41c48c38aa9a7014 (2025-10-07). The 'rss' GET parameter receives data that is passed directly to the unserialize() function without validation. This allows a remote, unauthenticated attacker to inject arbitrary PHP objects, causing the application to process them and leading to errors or a denial of service.

Project Subscriptions

Vendors Products
Miczflor Subscribe
Rpi-jukebox-rfid Subscribe
Sourcefabric Subscribe
Phoniebox Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 31 Dec 2025 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Sourcefabric
Sourcefabric phoniebox
CPEs cpe:2.3:a:sourcefabric:phoniebox:*:*:*:*:*:*:*:*
Vendors & Products Sourcefabric
Sourcefabric phoniebox

Sun, 21 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Miczflor
Miczflor rpi-jukebox-rfid
Vendors & Products Miczflor
Miczflor rpi-jukebox-rfid

Thu, 18 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-502
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 20:45:00 +0000

Type Values Removed Values Added
Description An insecure deserialization vulnerability exists in the rss-mp3.php script of the MiczFlor RPi-Jukebox-RFID project through commit 4b2334f0ae0e87c0568876fc41c48c38aa9a7014 (2025-10-07). The 'rss' GET parameter receives data that is passed directly to the unserialize() function without validation. This allows a remote, unauthenticated attacker to inject arbitrary PHP objects, causing the application to process them and leading to errors or a denial of service.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-12-18T21:17:52.996Z

Reserved: 2025-10-27T00:00:00.000Z

Link: CVE-2025-63951

cve-icon Vulnrichment

Updated: 2025-12-18T21:16:38.171Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-18T21:15:55.070

Modified: 2025-12-31T19:27:41.563

Link: CVE-2025-63951

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-21T21:15:01Z

Weaknesses