CVE-2026-25200
9.8Samsung Electronics · MagicINFO 9 Server
Samsung MagicINFO 9 Server contains an unrestricted file upload vulnerability that allows unauthenticated attackers to perform Stored Cross-Site Scripting, potentially leading to account takeover.
Executive summary
A critical vulnerability in Samsung MagicINFO 9 Server allows unauthenticated attackers to execute arbitrary code or hijack user sessions via malicious file uploads.
Vulnerability
This flaw stems from an unrestricted upload of dangerous file types (CWE-434), which permits unauthenticated remote attackers to upload crafted HTML files to the server. The lack of proper validation on the upload function enables Stored Cross-Site Scripting, which can be leveraged to compromise administrative sessions.
Business impact
The ability for an unauthenticated attacker to achieve account takeover poses a severe risk to organizational data integrity and system confidentiality. Given the CVSS score of 9.8, this vulnerability is classified as critical, as it provides an easy path for unauthorized actors to gain full control over the application, potentially leading to widespread internal system compromise and data exfiltration.
Remediation
Immediate Action: Upgrade Samsung MagicINFO 9 Server to version 21.1090.1 or higher immediately to resolve the unrestricted file upload flaw.
Proactive Monitoring: Review web server access logs for anomalous file upload activity, particularly requests involving HTML or script-based file types directed at the MagicINFO server.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized file uploads and restrict access to the file upload endpoint to known, trusted IP addresses.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The critical nature of this vulnerability, combined with the lack of required authentication for exploitation, necessitates immediate patching. Security teams should prioritize the update to version 21.1090.1 across all instances of the MagicINFO 9 Server to prevent potential account takeover and unauthorized system access.
More Samsung Electronics CVEs all →
History
- Disclosed CVE record published
- Published in the daily brief critical section, carried in 2 daily briefs, Feb 2 to Feb 3
- Analyst report written