Samsung MagicINFO 9 Server – database account and password are hardcoded (CVE-2026-25202)
CVE number = CVE-2026-25202
Samsung reference = SVE-2025-50085
The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server. This issue affects MagicINFO 9 Server: less than version 21.1090.1.
MagicInfo 9 Server is Samsung’s central management server for its MagicINFO 9 digital signage platform.
- Weakness : The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.
- Patch information : Remove hardcoded data

I am one of the editors here at www.systemtek.co.uk I am a UK based technology professional, with an interest in computer security and telecoms.
