CVE-2025-53082
三星数据管理服务器(DMS)存在相对路径遍历漏洞(CWE-23),允许攻击者通过特定授权IP删除任意文件。三星建议用户联系客服更新软件,并断开设备与互联网连接以避免风险。 2025-7-29 11:16:0 Author: claroty.com(查看原文) 阅读量:1 收藏

High Threat

CWE-23 RELATIVE PATH TRAVERSAL:

An 'Arbitary File Deletion' in Samsung DMS (Data Management Server) allows attackers to delete arbitary files from unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses.

Samsung recommends users to contact a Samsung call center or installer for a software update.

This product is not intended to be connected to the Internet, so please disconnect it from the Internet. Refer to the following statement in the manual: "Use this product only in a separate dedicated network. Samsung Electronics is not liable for any problems caused by connecting it to the Internet or an intranet."


文章来源: https://claroty.com/team82/disclosure-dashboard/cve-2025-53082
如有侵权请联系:admin#unsafe.sh