CVE-2025-53080

EUVD-2025-22973
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) allows authenticated attackers to create arbitrary files in unintended locations on the filesystem
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.1 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H
samsung.tv_applianceCNA
7.1 HIGH
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
Affected Products (NVD)
VendorProductVersion
samsungdata_management_server_firmware
2.0.0 ≤
𝑥
< 2.3.13.1
samsungdata_management_server_firmware
2.5.0.17 ≤
𝑥
< 2.6.14.1
samsungdata_management_server_firmware
2.7.0.15 ≤
𝑥
< 2.9.3.6
𝑥
= Vulnerable software versions