PT-2026-5607 · Samsung · Magicinfo 9 Server
Published
2026-02-02
·
Updated
2026-03-10
·
CVE-2026-25202
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
MagicINFO 9 Server versions prior to 21.1090.1
Description
The database account and password are hardcoded, which allows login with the account to manipulate the database. This compromises the integrity and confidentiality of the database.
Recommendations
Update MagicINFO 9 Server to version 21.1090.1 or later.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Magicinfo 9 Server