CVE-2025-20949: Samsung Members

Critical severity, CVSS 9.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Path traversal vulnerability in Samsung Members prior to version 5.0.00.11 allows attackers to read and write arbitrary file with the privilege of Samsung Members.

Affected products

  • Samsung Members: before 5.0.00.11 (fixed in 5.0.00.11)

Published 2025-05-07. Last modified 2026-06-17.