ZeroHour

CVE-2025-4632

KEVmoderate

Actively Exploited Path Traversal File Write in Samsung MagicINFO 9 Server

CISA: Samsung MagicINFO 9 Server Path Traversal Vulnerability

CVSS 3.1
9.8 critical
EPSS
24%p98
Published
()
KEV added
AI analysis

Samsung MagicINFO 9 Server, the web-based management server used to run Samsung digital signage deployments, contains a path traversal flaw (CWE-22) that allows an attacker to write arbitrary files with system authority. An attacker triggers the flaw by sending crafted path input containing directory traversal sequences, causing files to be written outside the intended location; because the write occurs with system-level privileges, it can enable remote code execution, persistence, or full compromise of the host server. Any organization running MagicINFO 9 Server — typically operators of Samsung commercial signage networks — is potentially affected. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on May 22, 2025, confirming exploitation in the wild, and EPSS places it in the 98th percentile with a 24.3% probability of exploitation within 30 days; no public proof-of-concept is known. Specific affected version ranges are not stated in the available data.

What to do: Immediately update MagicINFO 9 Server to the latest release per Samsung's security advisory, or if patching is not yet possible, restrict network and internet access to the server or discontinue use as required by the CISA KEV action (federal agencies must follow BOD 22-01 timelines). Hunt for signs of compromise — unexpected or newly written files, modified web content, or added web shells/accounts — since the flaw permits system-privileged file writes. Verify internet-exposed instances are remediated first.

Affected
Samsung MagicINFO 9 Server
Estimated exposure
moderate≈1,000–10,000 MagicINFO 9 Server deployments worldwide — Estimated from the on-prem deployment pattern of Samsung's signage management software: public internet scans typically show exposed MagicINFO servers in the low thousands, with a larger installed base on internal networks.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.

CISA Known Exploited Vulnerability
Affected
Samsung MagicINFO 9 Server
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
samsung
Products
magicinfo 9 server
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news