CVE-2025-53079
三星DMS服务器存在绝对路径遍历漏洞(CWE-36),允许攻击者读取敏感文件。建议用户联系客服更新软件,并断开互联网连接。 2025-7-29 11:12:0 Author: claroty.com(查看原文) 阅读量:0 收藏

Medium Threat

CWE-36 ABSOLUTE PATH TRAVERSAL:

Absolute Path Traversal in Samsung DMS (Data Management Server) allows authenticated attacker (Administrator) to read sensitive files.

Samsung recommends users to contact a Samsung call center or installer for a software update.

This product is not intended to be connected to the Internet, so please disconnect it from the Internet. Refer to the following statement in the manual: "Use this product only in a separate dedicated network. Samsung Electronics is not liable for any problems caused by connecting it to the Internet or an intranet."


文章来源: https://claroty.com/team82/disclosure-dashboard/cve-2025-53079
如有侵权请联系:admin#unsafe.sh