CVE-2025-53081
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
29/07/2025
Last modified:
11/08/2025
Description
An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses.
Impact
Base Score 3.x
6.40
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:samsung:data_management_server_firmware:*:*:*:*:*:*:*:* | 2.0.0 (including) | 2.3.13.1 (excluding) |
| cpe:2.3:o:samsung:data_management_server_firmware:*:*:*:*:*:*:*:* | 2.5.0.17 (including) | 2.6.14.1 (excluding) |
| cpe:2.3:o:samsung:data_management_server_firmware:*:*:*:*:*:*:*:* | 2.7.0.15 (including) | 2.9.3.6 (excluding) |
| cpe:2.3:h:samsung:data_management_server:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



