Home

Description

Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via write file to system

PUBLISHED Reserved 2025-06-24 | Published 2025-07-29 | Updated 2025-07-29 | Assigner samsung.tv_appliance




HIGH: 8.0CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-502 Deserialization of Untrusted Data

Product status

Default status
unaffected

2.0.0 (custom) before 2.3.13.1
affected

2.5.0.17 (custom) before 2.6.14.1
affected

2.7.0.15 (custom) before 2.9.3.6
affected

Credits

Noam Moshe of Claroty Team82 finder

References

security.samsungda.com/securityUpdates.html

cve.org (CVE-2025-53078)

nvd.nist.gov (CVE-2025-53078)

Download JSON