CVE-2025-49182: Sick Media Server

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Files in the source code contain login credentials for the admin user and the property configuration password, allowing an attacker to get full access to the application.

Affected products

  • Sick Media Server: before 1.5 (fixed in 1.5)

Published 2025-06-12. Last modified 2026-06-17.