PT-2026-5606 · Samsung · Magicinfo 9 Server
CVE-2026-25201
·
Publicado
2026-02-02
·
Atualizado
2026-03-10
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
MagicINFO 9 Server versions prior to 21.1090.1
Description
An unauthenticated user can upload arbitrary files, potentially leading to remote code execution and privilege escalation. The issue allows for the upload of files without authentication, which can then be used to execute code on the system.
Recommendations
Update MagicINFO 9 Server to version 21.1090.1 or later.
Correção
LPE
RCE
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Magicinfo 9 Server