← Vulnerability feed

Vulnerability record · CVE-2025-54445 · published 23 July 2025

CVE-2025-54445: Samsung magicinfo 9 server xml external entity (xxe) vulnerability

Samsung · Magicinfo 9 Server

Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Server Side Request Forgery.This issue affects MagicINFO 9 Server: less than 21.1080.0.

9.8 CVSS 3.1 Critical EPSS 12% · top 4.0% CWE-611 · XML external entity (XXE)
9.8CVSS 3.1 base score
12%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Server Side Request Forgery.This issue affects MagicINFO 9 Server: less than 21.1080.0.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-54445 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-4632Samsung MagicINFO 9 Server path traversal allows arbitrary file writeSamsung MagicINFO 9 Server before version 21.1052 contains a path traversal flaw (CWE-22) that lets an attacker write arbitrary files with system aut…KEVEPSS 24%analysed9.8CVE-2024-7399Samsung MagicINFO 9 Server path traversal allows arbitrary file writeSamsung MagicINFO 9 Server before version 21.1050 contains a path traversal flaw (CWE-22) that also enables unrestricted file upload (CWE-434), letti…KEVEPSS 92%analysed9.8CVE-2026-25202Samsung magicinfo 9 server hard-coded credentials vulnerabilityThe database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects M…EPSS 0.46%9.8CVE-2026-25200Samsung magicinfo 9 server unrestricted file upload vulnerabilityA vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in …EPSS 0.51%9.8CVE-2025-54455Samsung magicinfo 9 server hard-coded credentials vulnerabilityUse of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects MagicINFO 9 Ser…EPSS 0.55%9.8CVE-2025-54448Samsung magicinfo 9 server unrestricted file upload vulnerabilityUnrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…EPSS 0.60%9.8CVE-2025-54449Samsung magicinfo 9 server unrestricted file upload vulnerabilityUnrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects Magi…EPSS 0.63%9.8CVE-2025-54450Samsung magicinfo 9 server path traversal vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code In…EPSS 0.59%

Source: NIST National Vulnerability Database (record CVE-2025-54445), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.