Home

Description

An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses.

PUBLISHED Reserved 2025-06-24 | Published 2025-07-29 | Updated 2025-07-29 | Assigner samsung.tv_appliance




MEDIUM: 6.4CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

Problem types

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

Default status
unaffected

2.0.0 (custom) before 2.3.13.1
affected

2.5.0.17 (custom) before 2.6.14.1
affected

2.7.0.15 (custom) before 2.9.3.6
affected

Credits

Noam Moshe of Claroty Team82 finder

References

security.samsungda.com/securityUpdates.html

cve.org (CVE-2025-53081)

nvd.nist.gov (CVE-2025-53081)