CVE-2026-25200Disclosure(samsung / magicinfo_9_server)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch samsung magicinfo_9_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in account takeover This issue affects MagicINFO 9 Server: less than 21.1090.1.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • magicinfo_9_server

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 3 mentions (2026-02-02); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
magicinfo_9_server

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-02-02: 3Mentions · 2026-02-05: 2Mentions · 2026-02-07: 1Patch / Workaround · 2026-02-02: 1Patch / Workaround · 2026-02-05: 1Technical Details · 2026-02-02: 3Technical Details · 2026-02-05: 2Technical Details · 2026-02-07: 102-0202-0502-07
Signal classification2 categories
Disclosure
466.7%
Patch
233.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-023
Disclosure2Patch1
2026-02-052
Disclosure1Patch1
2026-02-071
Disclosure1
Full discourse6 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-25200 (CVSS:9.8, CRITICAL) is Awaiting Analysis. A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Sto..https://nvd.nist.gov/vuln/detail/CVE-2026-25200 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-25200, highlighting a critical file‑upload flaw in MagicInfo9 Server, but provides no evidence of exploitation, PoC, or mitigation.

    0000034
    171 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-25200 (CVSS:9.8, CRITICAL) is Awaiting Analysis. A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Sto..https://nvd.nist.gov/vuln/detail/CVE-2026-25200 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE-2026-25200, a critical flaw in MagicInfo9 Server that permits authenticated users to upload HTML files without proper authentication, potentially leading to exploitation. No PoC, exploit code, patch, or active usage information is included.

    00000101
    171 followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    🔍 𝐒𝐢𝐠𝐧𝐚𝐠𝐞 𝐇𝐢𝐣𝐚𝐜𝐤: 𝐒𝐚𝐦𝐬𝐮𝐧𝐠 𝐌𝐚𝐠𝐢𝐜𝐈𝐧𝐟𝐨𝟗 𝐅𝐥𝐚𝐰𝐬 (𝐂𝐕𝐒𝐒 𝟗.𝟖) 𝐄𝐱𝐩𝐨𝐬𝐞 𝐒𝐞𝐫𝐯𝐞𝐫𝐬 • Samsung MagicInfo9 Server, used for digital signage, contains three severe security vulnerabilities. • Two critical flaws, CVE-2026-25202 (hardcoded credentials) and CVE-2026-25200 (Stored XSS), have a CVSS score of 9.8. • A remote code execution vulnerability, CVE-2026-25201 (CVSS 8.8), also affects the server. • All versions of MagicINFO 9 Server prior to 21.1090.1 are vulnerable and require an immediate upgrade. Samsung MagicInfo9 Server versions older than 21.1090.1 are exposed to unauthenticated attackers due to critical vulnerabilities, including hardcoded credentials and remote code execution, necessitating an immediate upgrade to version 21.1090.1 or later.

    Post summary

    Samsung MagicInfo9 Server is affected by three critical CVEs—CVE-2026-25202 (hardcoded credentials), CVE-2026-25200 (Stored XSS), and CVE-2026-25201 (remote code execution)—all with high CVSS scores; all versions prior to 21.1090.1 must be upgraded immediately to mitigate these risks.

    0000092
    64 followersView on X
  • Säkerhetsbloggen@Sakerhetsblogg
    Disclosure

    CVE-2026-25200: En sårbarhet i MagicInfo 9 Server tillåter otillåten HTML-uppladdning av autentiserade användare, vilket leder till Stored XSS. Detta kan resultera i allvarlig attacker och kontoövertagande. #säkerhet #cybersäkerhet #CVE

    Post summary

    The post announces CVE‑2026‑25200, highlighting an unauthorized HTML upload that causes Stored XSS in MagicInfo 9 Server, potentially enabling account takeover.

    0000036
    7 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25200: CRITICAL] Critical vulnerability in MagicInfo9 Server allows unauthorized HTML file uploads, leading to Stored XSS & potential account takeover. Update versions less than 21.1090.1 ASAP.#cve,CVE-2026-25200,#cybersecurity https://cvefind.com/CVE-2026-25200

    Post summary

    A critical MagicInfo9 Server vulnerability (CVE‑2026‑25200) allows unauthorized HTML uploads that can trigger stored XSS and account takeover; users are advised to update to version 21.1090.1 or later.

    00000114
    583 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25200 - Critical A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in account takeover This issue affects ... https://www.thehackerwire.com/vulnerability/CVE-2026-25200/ https://t.co/mhK75YEs2q

    Post summary

    The message announces a critical vulnerability (CVE-2026-25200) in MagicInfo9 Server that permits unauthenticated HTML uploads, leading to stored XSS and potential account takeover.

    0000055
    113 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsamsungmagicinfo_9_server---

Explore more