logo

Signage Hijack: Samsung MagicInfo9 Flaws (CVSS 9.8) Expose Servers

ID: 476a0878-3261-5e0f-9a84-d9851d2509ea

STIX ID: report--476a0878-3261-5e0f-9a84-d9851d2509ea

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-05

Date Updated: 2026-04-23

Author: Ddos

...
...

Samsung MagicInfo9 Server contains three high-severity vulnerabilities—hardcoded database credentials (CVE-2026-25202, CVSS 9.8), unauthenticated arbitrary file upload enabling remote code execution (CVE-2026-25201, CVSS 8.8), and unauthenticated HTML upload leading to stored XSS (CVE-2026-25200, CVSS 9.8)—affecting all versions prior to 21.1090.1; administrators are advised to upgrade immediately to 21.1090.1 or later to eliminate these risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.