CVE-2026-25202: Critical severity Samsung MagicINFO 9 Server vulnerability
Published Feb 2, 2026
·Updated
The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects MagicINFO 9 Server: less than 21.1090.1.
Affected Software
2 affected components
Samsung MagicINFO 9 Server<21.1090.1
Samsung MagicINFO 9 Server<21.1090.1
Event History
Feb 2, 2026
CVE Published
via MITRE·04:49 AM
Data Sourced
via MITRE·04:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-25202?
CVE-2026-25202 has a high severity due to the hardcoded database credentials that allow unauthorized access.
2
How do I fix CVE-2026-25202?
To fix CVE-2026-25202, update your MagicINFO 9 Server to version 21.1090.1 or later where the hardcoded credentials issue is resolved.
3
What are the potential impacts of CVE-2026-25202?
The potential impacts of CVE-2026-25202 include unauthorized database manipulation and data leakage.
4
Is CVE-2026-25202 present in all versions of MagicINFO 9 Server?
CVE-2026-25202 is present in all versions of MagicINFO 9 Server prior to 21.1090.1.
5
Who is affected by CVE-2026-25202?
Organizations using MagicINFO 9 Server versions below 21.1090.1 are affected by CVE-2026-25202.