CVE-2025-54454
BaseFortify
Publication date: 2025-07-23
Last updated on: 2025-07-28
Assigner: Samsung TV & Appliance
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| samsung | magicinfo_9_server | to 21.1080.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-798 | The product contains hard-coded credentials, such as a password or cryptographic key. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a Use of Hard-coded Credentials issue in Samsung Electronics MagicINFO 9 Server (versions less than 21.1080.0). It allows an attacker to bypass authentication mechanisms, meaning they can gain unauthorized access to the system without valid credentials.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized access to the MagicINFO 9 Server, potentially allowing attackers to compromise confidentiality and integrity of the system and its data. According to the CVSS score (9.1), it is a high-severity issue that can result in significant impact without requiring user interaction or privileges.