VYPR
Medium severity5.4NVD Advisory· Published Nov 26, 2025· Updated Jun 17, 2026

CVE-2025-66258

CVE-2025-66258

Description

Stored Cross-Site Scripting via XML Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Stored XSS via crafted filenames injected into patchlist.xml. User-controlled filenames are directly concatenated into patchlist.xml without encoding, allowing injection of malicious JavaScript payloads via crafted filenames (e.g., .bin). The XSS executes when ajax.js processes and renders the XML file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

24

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.