CVE-2026-25202Disclosure(samsung / magicinfo_9_server)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch samsung magicinfo_9_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects MagicINFO 9 Server: less than 21.1090.1.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-798

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • magicinfo_9_server

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 7 classified signals
  • Peaked 3d ago at 4 mentions (2026-02-02); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
magicinfo_9_server

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-02-02: 4Mentions · 2026-02-05: 1Mentions · 2026-02-07: 1Mentions · 2026-02-26: 1Patch / Workaround · 2026-02-05: 1Technical Details · 2026-02-02: 3Technical Details · 2026-02-05: 1Technical Details · 2026-02-07: 1Technical Details · 2026-02-26: 102-0202-0502-0702-26
Signal classification1 categories
Disclosure
7100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-024
Disclosure4
2026-02-051
Disclosure1
2026-02-071
Disclosure1
2026-02-261
Disclosure1
Full discourse7 posts
  • 듀나@selentia01
    Disclosure

    CVE-2026-25202 (CVSS 9.8) 보안적으로 굉장히 재미있는 사례인데 삼성 MagicINFO 9 Server 코드 내부에 DB 계정/비밀번호가 하드코딩되어 있었습니다. CNA 벡터(=삼성 내부 평가)를 쉽게 풀어서 쓰면 1. 외부에서 접근할 수 있고 2. 로그인이나 인증 없이 3. 서버 데이터를 조회/변경/삭제할 수 있습니다. 왜 군대 PC 비밀번호 포스트잇에 써두는 걸 기업이 하고 있는 거임;

    Post summary

    The post reveals that Samsung MagicINFO 9 Server contains hardcoded database credentials, enabling unauthenticated external access to view, modify, or delete server data, with a CVSS score of 9.8.

    31070556
    161 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-25202: CRITICAL] Critical security issue found in MagicINFO 9 Server versions below 21.1090.1! Hardcoded database account and password allow unauthorized access. #cybersecurity#cve,CVE-2026-25202,#cybersecurity https://cvefind.com/CVE-2026-25202

    Post summary

    CVE‑2026‑25202 exposes a critical flaw in MagicINFO 9 Server due to hardcoded database credentials, enabling unauthorized access; no PoC, exploit, or patch information is included.

    1000089
    583 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-25202 (CVSS:9.8, CRITICAL) is Awaiting Analysis. The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo..https://nvd.nist.gov/vuln/detail/CVE-2026-25202 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-25202 is a critical flaw involving hardcoded credentials in MagicInfo, with CVSS 9.8, currently awaiting analysis and lacking PoC, exploit, or patch details.

    0000045
    171 followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    🔍 𝐒𝐢𝐠𝐧𝐚𝐠𝐞 𝐇𝐢𝐣𝐚𝐜𝐤: 𝐒𝐚𝐦𝐬𝐮𝐧𝐠 𝐌𝐚𝐠𝐢𝐜𝐈𝐧𝐟𝐨𝟗 𝐅𝐥𝐚𝐰𝐬 (𝐂𝐕𝐒𝐒 𝟗.𝟖) 𝐄𝐱𝐩𝐨𝐬𝐞 𝐒𝐞𝐫𝐯𝐞𝐫𝐬 • Samsung MagicInfo9 Server, used for digital signage, contains three severe security vulnerabilities. • Two critical flaws, CVE-2026-25202 (hardcoded credentials) and CVE-2026-25200 (Stored XSS), have a CVSS score of 9.8. • A remote code execution vulnerability, CVE-2026-25201 (CVSS 8.8), also affects the server. • All versions of MagicINFO 9 Server prior to 21.1090.1 are vulnerable and require an immediate upgrade. Samsung MagicInfo9 Server versions older than 21.1090.1 are exposed to unauthenticated attackers due to critical vulnerabilities, including hardcoded credentials and remote code execution, necessitating an immediate upgrade to version 21.1090.1 or later.

    Post summary

    Samsung MagicInfo9 Server is affected by three severe CVEs (hardcoded credentials, stored XSS, and RCE) with CVSS scores up to 9.8, and an immediate upgrade to version 21.1090.1 or later is recommended.

    0000092
    64 followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    Samsung MagicINFO 9 Server - database account and password are hardcoded (CVE-2026-25202) #CVE202625202 #CyberSecurity #Samsung https://www.systemtek.co.uk/?p=48183 https://t.co/DlFT9ZTyVe

    Post summary

    A hardcoded database credential vulnerability (CVE‑2026‑25202) in Samsung MagicINFO 9 Server has been disclosed, but no PoC, exploit, or patch details are provided.

    0000060
    1.8K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting Samsung Electronics MagicINFO 9 Server (CVE-2026-25202) https://vuldb.com/?id.343684

    Post summary

    A severity increase is announced for CVE-2026-25202, a vulnerability affecting Samsung Electronics MagicINFO 9 Server, with a reference to a vulnerability database entry.

    0000099
    2.1K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25202 - Critical The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects MagicINFO 9 Server: less than 21.1090.1. https://www.thehackerwire.com/vulnerability/CVE-2026-25202/ https://t.co/y5xKRVVSy8

    Post summary

    CVE-2026-25202 reveals that MagicINFO 9 Server stores database credentials in clear text, allowing attackers to log in and manipulate the database. No PoC, exploit, or patch is mentioned in the text.

    0000061
    113 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsamsungmagicinfo_9_server---

Explore more