Description
PostgreSQL SQL Injection (status_sql.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform SQL injection via sw1 and sw2 parameters in status_sql.php.
The `status_sql.php` endpoint constructs SQL UPDATE queries by directly concatenating user-controlled `sw1` and `sw2` parameters without using parameterized queries or `pg_escape_string()`. While PostgreSQL's `pg_exec` limitations prevent stacked queries, attackers can inject subqueries for data exfiltration and leverage verbose error messages for reconnaissance.
Published: 2025-11-26
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 03 Dec 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Dbbroadcast mozart Dds Next 100
Dbbroadcast mozart Dds Next 1000
Dbbroadcast mozart Dds Next 1000 Firmware
Dbbroadcast mozart Dds Next 100 Firmware
Dbbroadcast mozart Dds Next 2000
Dbbroadcast mozart Dds Next 2000 Firmware
Dbbroadcast mozart Dds Next 30
Dbbroadcast mozart Dds Next 300
Dbbroadcast mozart Dds Next 3000
Dbbroadcast mozart Dds Next 3000 Firmware
Dbbroadcast mozart Dds Next 300 Firmware
Dbbroadcast mozart Dds Next 30 Firmware
Dbbroadcast mozart Dds Next 3500
Dbbroadcast mozart Dds Next 3500 Firmware
Dbbroadcast mozart Dds Next 50
Dbbroadcast mozart Dds Next 500
Dbbroadcast mozart Dds Next 500 Firmware
Dbbroadcast mozart Dds Next 50 Firmware
Dbbroadcast mozart Dds Next 6000
Dbbroadcast mozart Dds Next 6000 Firmware
Dbbroadcast mozart Dds Next 7000
Dbbroadcast mozart Dds Next 7000 Firmware
Dbbroadcast mozart Next 100
Dbbroadcast mozart Next 1000
Dbbroadcast mozart Next 1000 Firmware
Dbbroadcast mozart Next 100 Firmware
Dbbroadcast mozart Next 2000
Dbbroadcast mozart Next 2000 Firmware
Dbbroadcast mozart Next 30
Dbbroadcast mozart Next 300
Dbbroadcast mozart Next 3000
Dbbroadcast mozart Next 3000 Firmware
Dbbroadcast mozart Next 300 Firmware
Dbbroadcast mozart Next 30 Firmware
Dbbroadcast mozart Next 3500
Dbbroadcast mozart Next 3500 Firmware
Dbbroadcast mozart Next 50
Dbbroadcast mozart Next 500
Dbbroadcast mozart Next 500 Firmware
Dbbroadcast mozart Next 50 Firmware
Dbbroadcast mozart Next 6000
Dbbroadcast mozart Next 6000 Firmware
Dbbroadcast mozart Next 7000
Dbbroadcast mozart Next 7000 Firmware
CPEs cpe:2.3:h:dbbroadcast:mozart_dds_next_1000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_100:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_2000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_3000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_300:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_30:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_3500:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_500:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_50:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_6000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_dds_next_7000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_1000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_100:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_2000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_3000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_300:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_30:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_3500:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_500:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_50:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_6000:-:*:*:*:*:*:*:*
cpe:2.3:h:dbbroadcast:mozart_next_7000:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_1000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_2000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_3000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_30_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_3500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_50_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_6000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_dds_next_7000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_1000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_2000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_3000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_300_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_30_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_3500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_50_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_6000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:dbbroadcast:mozart_next_7000_firmware:-:*:*:*:*:*:*:*
Vendors & Products Dbbroadcast mozart Dds Next 100
Dbbroadcast mozart Dds Next 1000
Dbbroadcast mozart Dds Next 1000 Firmware
Dbbroadcast mozart Dds Next 100 Firmware
Dbbroadcast mozart Dds Next 2000
Dbbroadcast mozart Dds Next 2000 Firmware
Dbbroadcast mozart Dds Next 30
Dbbroadcast mozart Dds Next 300
Dbbroadcast mozart Dds Next 3000
Dbbroadcast mozart Dds Next 3000 Firmware
Dbbroadcast mozart Dds Next 300 Firmware
Dbbroadcast mozart Dds Next 30 Firmware
Dbbroadcast mozart Dds Next 3500
Dbbroadcast mozart Dds Next 3500 Firmware
Dbbroadcast mozart Dds Next 50
Dbbroadcast mozart Dds Next 500
Dbbroadcast mozart Dds Next 500 Firmware
Dbbroadcast mozart Dds Next 50 Firmware
Dbbroadcast mozart Dds Next 6000
Dbbroadcast mozart Dds Next 6000 Firmware
Dbbroadcast mozart Dds Next 7000
Dbbroadcast mozart Dds Next 7000 Firmware
Dbbroadcast mozart Next 100
Dbbroadcast mozart Next 1000
Dbbroadcast mozart Next 1000 Firmware
Dbbroadcast mozart Next 100 Firmware
Dbbroadcast mozart Next 2000
Dbbroadcast mozart Next 2000 Firmware
Dbbroadcast mozart Next 30
Dbbroadcast mozart Next 300
Dbbroadcast mozart Next 3000
Dbbroadcast mozart Next 3000 Firmware
Dbbroadcast mozart Next 300 Firmware
Dbbroadcast mozart Next 30 Firmware
Dbbroadcast mozart Next 3500
Dbbroadcast mozart Next 3500 Firmware
Dbbroadcast mozart Next 50
Dbbroadcast mozart Next 500
Dbbroadcast mozart Next 500 Firmware
Dbbroadcast mozart Next 50 Firmware
Dbbroadcast mozart Next 6000
Dbbroadcast mozart Next 6000 Firmware
Dbbroadcast mozart Next 7000
Dbbroadcast mozart Next 7000 Firmware
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Thu, 27 Nov 2025 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Dbbroadcast
Dbbroadcast mozart Fm Transmitter
Vendors & Products Dbbroadcast
Dbbroadcast mozart Fm Transmitter

Wed, 26 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Nov 2025 01:15:00 +0000

Type Values Removed Values Added
Description PostgreSQL SQL Injection (status_sql.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform SQL injection via sw1 and sw2 parameters in status_sql.php. The `status_sql.php` endpoint constructs SQL UPDATE queries by directly concatenating user-controlled `sw1` and `sw2` parameters without using parameterized queries or `pg_escape_string()`. While PostgreSQL's `pg_exec` limitations prevent stacked queries, attackers can inject subqueries for data exfiltration and leverage verbose error messages for reconnaissance.
Title PostgreSQL SQL Injection (status_sql.php)
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:L/SI:N/SA:N'}


Subscriptions

Dbbroadcast Mozart Dds Next 100 Mozart Dds Next 1000 Mozart Dds Next 1000 Firmware Mozart Dds Next 100 Firmware Mozart Dds Next 2000 Mozart Dds Next 2000 Firmware Mozart Dds Next 30 Mozart Dds Next 300 Mozart Dds Next 3000 Mozart Dds Next 3000 Firmware Mozart Dds Next 300 Firmware Mozart Dds Next 30 Firmware Mozart Dds Next 3500 Mozart Dds Next 3500 Firmware Mozart Dds Next 50 Mozart Dds Next 500 Mozart Dds Next 500 Firmware Mozart Dds Next 50 Firmware Mozart Dds Next 6000 Mozart Dds Next 6000 Firmware Mozart Dds Next 7000 Mozart Dds Next 7000 Firmware Mozart Fm Transmitter Mozart Next 100 Mozart Next 1000 Mozart Next 1000 Firmware Mozart Next 100 Firmware Mozart Next 2000 Mozart Next 2000 Firmware Mozart Next 30 Mozart Next 300 Mozart Next 3000 Mozart Next 3000 Firmware Mozart Next 300 Firmware Mozart Next 30 Firmware Mozart Next 3500 Mozart Next 3500 Firmware Mozart Next 50 Mozart Next 500 Mozart Next 500 Firmware Mozart Next 50 Firmware Mozart Next 6000 Mozart Next 6000 Firmware Mozart Next 7000 Mozart Next 7000 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Gridware

Published:

Updated: 2025-11-26T15:06:21.454Z

Reserved: 2025-11-26T00:21:58.504Z

Link: CVE-2025-66260

cve-icon Vulnrichment

Updated: 2025-11-26T15:06:02.989Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-26T01:16:09.440

Modified: 2025-12-03T16:51:12.470

Link: CVE-2025-66260

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-27T09:45:50Z

Weaknesses