CVE-2025-4632
KEVmoderateActively Exploited Path Traversal File Write in Samsung MagicINFO 9 Server
CISA: Samsung MagicINFO 9 Server Path Traversal Vulnerability
Samsung MagicINFO 9 Server, the web-based management server used to run Samsung digital signage deployments, contains a path traversal flaw (CWE-22) that allows an attacker to write arbitrary files with system authority. An attacker triggers the flaw by sending crafted path input containing directory traversal sequences, causing files to be written outside the intended location; because the write occurs with system-level privileges, it can enable remote code execution, persistence, or full compromise of the host server. Any organization running MagicINFO 9 Server — typically operators of Samsung commercial signage networks — is potentially affected. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on May 22, 2025, confirming exploitation in the wild, and EPSS places it in the 98th percentile with a 24.3% probability of exploitation within 30 days; no public proof-of-concept is known. Specific affected version ranges are not stated in the available data.
What to do: Immediately update MagicINFO 9 Server to the latest release per Samsung's security advisory, or if patching is not yet possible, restrict network and internet access to the server or discontinue use as required by the CISA KEV action (federal agencies must follow BOD 22-01 timelines). Hunt for signs of compromise — unexpected or newly written files, modified web content, or added web shells/accounts — since the flaw permits system-privileged file writes. Verify internet-exposed instances are remediated first.
| Samsung MagicINFO 9 Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.
- Affected
- Samsung MagicINFO 9 Server
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- samsung
- Products
- magicinfo 9 server
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H