Signage Hijack: Samsung MagicInfo9 Flaws (CVSS 9.8) Expose Servers
ID: 476a0878-3261-5e0f-9a84-d9851d2509ea
STIX ID: report--476a0878-3261-5e0f-9a84-d9851d2509ea
Feed Name: securityonline.info
Threat Score
Samsung MagicInfo9 Server contains three high-severity vulnerabilities—hardcoded database credentials (CVE-2026-25202, CVSS 9.8), unauthenticated arbitrary file upload enabling remote code execution (CVE-2026-25201, CVSS 8.8), and unauthenticated HTML upload leading to stored XSS (CVE-2026-25200, CVSS 9.8)—affecting all versions prior to 21.1090.1; administrators are advised to upgrade immediately to 21.1090.1 or later to eliminate these risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
