PT-2025-30537 · Samsung · Magicinfo 9 Server

CVE-2025-54449

·

Publicado

2025-07-23

·

Atualizado

2025-07-28

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MagicINFO 9 Server versions prior to 21.1080.0
Description A code injection issue exists due to the unrestricted upload of files with dangerous types. This allows for potential code execution.
Recommendations Update to version 21.1080.0.

Correção

RCE

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-54449
ZDI-25-665

Produtos afetados

Magicinfo 9 Server