CVE-2025-54445

CRITICAL WAF: High
CVSS 9.8 Published: 2025-07-23
CWE-611

Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Server Side Request Forgery.This issue affects MagicINFO 9 Server: less than 21.1080.0.

WAF Coverage Analysis

XML External Entity (XXE) High WAF Coverage

OWASP: A05:2021 Security Misconfiguration

941xxx - XSS / XXE

Affected Software

VendorProductVersion
samsungmagicinfo_9_serverup to 21.1080.0

References

Back to CVE Database