CVE-2025-53078
CWE-502反序列化漏洞存在于三星DMS服务器中,允许攻击者通过写文件执行任意代码;建议用户更新软件并断开互联网连接;产品不支持互联网使用。 2025-7-29 11:11:0 Author: claroty.com(查看原文) 阅读量:0 收藏

High Threat

CWE-502 DESERIALIZATION OF UNTRUSTED DATA:

Deserialization of Untrusted Data in Samsung DMS (Data Management Server) allows attackers to execute arbitary code via write file to system.

Samsung recommends users to contact a Samsung call center or installer for a software update.

This product is not intended to be connected to the Internet, so please disconnect it from the Internet. Refer to the following statement in the manual: "Use this product only in a separate dedicated network. Samsung Electronics is not liable for any problems caused by connecting it to the Internet or an intranet."


文章来源: https://claroty.com/team82/disclosure-dashboard/cve-2025-53078
如有侵权请联系:admin#unsafe.sh