Database Manipulation Risk in Samsung MagicInfo 9 Server
CVE-2026-25202

9.8CRITICAL

Key Information:

Vendor
CVE Published:
2 February 2026

What is CVE-2026-25202?

A serious vulnerability exists in Samsung MagicInfo 9 Server where the database account and password are hardcoded within the application. This flaw provides unauthorized users with the ability to log in and manipulate the database, potentially leading to data breaches or malicious modifications. Users are strongly advised to update to versions newer than 21.1090.1 to mitigate this risk and protect sensitive data.

Affected Version(s)

MagicINFO 9 Server 21.1090.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.