


Perceptive Security
SOC/SIEM Consultancy

The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects MagicINFO 9 …
Published:
1 februari 2026 om 23:00:00
Alert date:
2 februari 2026 om 06:01:15
Source:
nvd.nist.gov
Database & Storage, Enterprise Applications
A critical vulnerability in Samsung's MagicInfo9 Server allows unauthorized database access through hardcoded credentials. The hardcoded database account and password enable attackers to login and manipulate the database directly. This vulnerability affects MagicINFO 9 Server versions prior to 21.1090.1. The issue represents a significant security flaw as it provides direct database access without proper authentication. Organizations using affected versions should upgrade immediately to prevent unauthorized data manipulation.
Technical details
Mitigation steps:
Affected products:
MagicINFO 9 Server
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
