漏洞描述 Samsung Security Manager(SSM)是韩国三星(Samsung)公司的一套录像设备的中心管理平台,它支持站点群组管理、显示登记的设备列表、通过鼠标拖放或双击操作实现指定视频边框播放等。 SSM 1.31之前版本中存在安全漏洞。远程攻击者可通过发送HTTP PUT或MOVE请求,上传文件利用该漏洞执行任意代码。
相关漏洞推荐 POC CVE-2025-36845: Eveo URVE Web Manager - Server-Side Request Forgery POC CVE-2025-49533: Adobe Experience Manager Forms - Insecure Deserialization POC wp-all-in-one-wp-security-and-firewall-fpd: All In One WP Security & Firewall - Full Path Disclosure POC wp-better-wp-security-fpd: WordPress Plugin iThemes Security - Full Path Disclosure POC wp-duracelltomi-google-tag-manager-fpd: WordPress Plugin Google Tag Manager - Full Path Disclosure POC wp-all-in-one-wp-security-and-firewall-fpd: All In One WP Security & Firewall - Full Path Disclosure POC wp-better-wp-security-fpd: WordPress Plugin iThemes Security - Full Path Disclosure POC wp-better-wp-security-login-disclosure: WordPress Solid Security < 9.0.1 - Unauthenticated Login Page Disclosure POC wp-duracelltomi-google-tag-manager-fpd: WordPress Plugin Google Tag Manager - Full Path Disclosure Ksenia Security Lares 4.0 Home Automation 安全漏洞 ETAP Safety Manager 跨站脚本漏洞 POC CVE-2020-26836: SAP Solution Manager - Open Redirect POC bitrix-log-file-disclosure: Bitrix Site Manager - Log File Disclosure