CVE-2026-25201Disclosure(samsung / magicinfo_9_server)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch samsung magicinfo_9_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9 Server. This issue affects MagicINFO 9 Server: less than 21.1090.1.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • magicinfo_9_server

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-02); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
magicinfo_9_server

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-02-02: 2Mentions · 2026-02-05: 2Mentions · 2026-02-07: 1Patch / Workaround · 2026-02-05: 1Technical Details · 2026-02-02: 2Technical Details · 2026-02-05: 2Technical Details · 2026-02-07: 102-0202-0502-07
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-022
Disclosure2
2026-02-052
Disclosure1Patch1
2026-02-071
Disclosure1
Full discourse5 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-25201: HIGH] Critical security flaw in MagicINFO 9 Server (<21.1090.1) allows unauthenticated users to upload files for remote code execution, risking privilege escalation. #CyberSecurity#cve,CVE-2026-25201,#cybersecurity https://cvefind.com/CVE-2026-25201

    Post summary

    The post announces a high‑severity remote code execution vulnerability in MagicINFO 9 Server, detailing how unauthenticated file uploads lead to privilege escalation.

    10000115
    583 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-25201 (CVSS:8.8, HIGH) is Awaiting Analysis. An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9..https://nvd.nist.gov/vuln/detail/CVE-2026-25201 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-25201 is a high‑severity vulnerability in MagicInfo9 that permits unauthenticated users to upload arbitrary files for remote code execution and privilege escalation; no PoC, exploit, or patch information is provided.

    0000033
    171 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-25201 (CVSS:8.8, HIGH) is Awaiting Analysis. An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9..https://nvd.nist.gov/vuln/detail/CVE-2026-25201 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A newly disclosed high‑severity vulnerability (CVE-2026-25201) allows unauthenticated users to upload arbitrary files, resulting in remote code execution and privilege escalation in MagicInfo9.

    00000151
    171 followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    🔍 𝐒𝐢𝐠𝐧𝐚𝐠𝐞 𝐇𝐢𝐣𝐚𝐜𝐤: 𝐒𝐚𝐦𝐬𝐮𝐧𝐠 𝐌𝐚𝐠𝐢𝐜𝐈𝐧𝐟𝐨𝟗 𝐅𝐥𝐚𝐰𝐬 (𝐂𝐕𝐒𝐒 𝟗.𝟖) 𝐄𝐱𝐩𝐨𝐬𝐞 𝐒𝐞𝐫𝐯𝐞𝐫𝐬 • Samsung MagicInfo9 Server, used for digital signage, contains three severe security vulnerabilities. • Two critical flaws, CVE-2026-25202 (hardcoded credentials) and CVE-2026-25200 (Stored XSS), have a CVSS score of 9.8. • A remote code execution vulnerability, CVE-2026-25201 (CVSS 8.8), also affects the server. • All versions of MagicINFO 9 Server prior to 21.1090.1 are vulnerable and require an immediate upgrade. Samsung MagicInfo9 Server versions older than 21.1090.1 are exposed to unauthenticated attackers due to critical vulnerabilities, including hardcoded credentials and remote code execution, necessitating an immediate upgrade to version 21.1090.1 or later.

    Post summary

    Three critical vulnerabilities (CVE‑2026‑25202, CVE‑2026‑25200, CVE‑2026‑25201) in Samsung MagicInfo9 Server require an immediate upgrade to version 21.1090.1 or later.

    0000092
    64 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-25201 - High An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9 Server. This issue affects MagicINFO 9 Server: less than 21.1090.1. https://www.thehackerwire.com/vulnerability/CVE-2026-25201/ https://t.co/CPRxJRWFpk

    Post summary

    The tweet announces CVE-2026-25201, describing an unauthenticated RCE via file upload in MagicINFO 9 Server, but does not mention exploitation or patches.

    0000049
    113 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsamsungmagicinfo_9_server---

Explore more