듀나[verified]@selentia01Disclosure
The post reveals that Samsung MagicINFO 9 Server contains hardcoded database credentials, enabling unauthenticated external access to view, modify, or delete server data, with a CVSS score of 9.8.
PurpleOps[verified]@PurpleOps_ioDisclosure
Samsung MagicInfo9 Server is affected by three severe CVEs (hardcoded credentials, stored XSS, and RCE) with CVSS scores up to 9.8, and an immediate upgrade to version 21.1090.1 or later is recommended.
CVEFind.com@CveFindComDisclosure
CVE‑2026‑25202 exposes a critical flaw in MagicINFO 9 Server due to hardcoded database credentials, enabling unauthorized access; no PoC, exploit, or patch information is included.
CRAC Learning - Tech@cracbotDisclosure
CVE-2026-25202 is a critical flaw involving hardcoded credentials in MagicInfo, with CVSS 9.8, currently awaiting analysis and lacking PoC, exploit, or patch details.
SystemTek - Technology news website@SystemTek_UKDisclosure
A hardcoded database credential vulnerability (CVE‑2026‑25202) in Samsung MagicINFO 9 Server has been disclosed, but no PoC, exploit, or patch details are provided.
VulDB 🛡@vuldbDisclosure
A severity increase is announced for CVE-2026-25202, a vulnerability affecting Samsung Electronics MagicINFO 9 Server, with a reference to a vulnerability database entry.
The Hacker Wire@TheHackerWireDisclosure
CVE-2026-25202 reveals that MagicINFO 9 Server stores database credentials in clear text, allowing attackers to log in and manipulate the database. No PoC, exploit, or patch is mentioned in the text.