CVE-2025-53080: Samsung Data Management Server Firmware

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) allows authenticated attackers to create arbitrary files in unintended locations on the filesystem

Affected products

  • Samsung Data Management Server Firmware: from 2.0.0, before 2.3.13.1 (fixed in 2.3.13.1); from 2.5.0.17, before 2.6.14.1 (fixed in 2.6.14.1); from 2.7.0.15, before 2.9.3.6 (fixed in 2.9.3.6)

Published 2025-07-29. Last modified 2026-06-17.