CVE-2026-25202

The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects MagicINFO 9 Server: less than 21.1090.1.
References
Link Resource
https://security.samsungtv.com/securityUpdates Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:samsung:magicinfo_9_server:*:*:*:*:*:*:*:*

History

10 Mar 2026, 18:44

Type Values Removed Values Added
CPE cpe:2.3:a:samsung:magicinfo_9_server:*:*:*:*:*:*:*:*
References () https://security.samsungtv.com/securityUpdates - () https://security.samsungtv.com/securityUpdates - Vendor Advisory
First Time Samsung
Samsung magicinfo 9 Server
Summary
  • (es) La cuenta y la contraseña de la base de datos están codificadas de forma rígida, permitiendo el inicio de sesión con la cuenta para manipular la base de datos en el servidor MagicInfo9. Este problema afecta a MagicINFO 9 Server: versiones inferiores a 21.1090.1.

02 Feb 2026, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-02 05:16

Updated : 2026-03-10 18:44


NVD link : CVE-2026-25202

Mitre link : CVE-2026-25202

CVE.ORG link : CVE-2026-25202


JSON object : View

Products Affected

samsung

  • magicinfo_9_server
CWE
CWE-798

Use of Hard-coded Credentials