ZeroHour

CVE-2025-54453

moderate

Unauthenticated Path Traversal in Samsung MagicINFO 9 Server Enables Code Injection

CVSS 3.1
9.8 critical
EPSS
22%p98
Published
()
Modified
AI analysis

CVE-2025-54453 is a path traversal flaw (CWE-22) in Samsung MagicINFO 9 Server in which user-supplied pathnames are not properly restricted to an intended directory. Per its CVSS vector (AV:N/AC:L/PR:N/UI:N), the flaw is reachable over the network by an unauthenticated attacker with no user interaction, by sending crafted requests whose paths escape the restricted directory, which Samsung describes as leading to code injection. A successful attack effectively gives the attacker the ability to execute code on the server, with CVSS rating full (High) impact on confidentiality, integrity, and availability (9.8 Critical). Any organization running MagicINFO 9 Server below version 21.1080.0 is affected, with the greatest risk on digital-signage management servers that are exposed to the internet. Exploitation has not been confirmed: the flaw is not yet in CISA's KEV catalog and no public PoC is known, but its EPSS score of 21.9% (98th percentile) signals an elevated probability of exploitation in the next 30 days.

What to do: Upgrade MagicINFO 9 Server to version 21.1080.0 or later, which resolves this issue. Until patched, remove direct internet exposure (restrict the server to VPN or management networks) and review web server logs for path traversal patterns in requests. Verify the currently deployed version in the MagicINFO admin console before and after updating.

Affected
Samsung Electronics MagicINFO 9 Serverall versions prior to 21.1080.0
Estimated exposure
moderatelow thousands of internet-exposed MagicINFO 9 servers (per public scan data); total deployments including internal servers unknown — Samsung MagicINFO is a widely deployed digital-signage content management platform, and public internet-wide scans have surfaced MagicINFO 9 instances in the low thousands, so exposed systems plausibly number in the thousands while many…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.

Vendors
samsung
Products
magicinfo 9 server
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.