CVE-2025-54453
moderateUnauthenticated Path Traversal in Samsung MagicINFO 9 Server Enables Code Injection
CVE-2025-54453 is a path traversal flaw (CWE-22) in Samsung MagicINFO 9 Server in which user-supplied pathnames are not properly restricted to an intended directory. Per its CVSS vector (AV:N/AC:L/PR:N/UI:N), the flaw is reachable over the network by an unauthenticated attacker with no user interaction, by sending crafted requests whose paths escape the restricted directory, which Samsung describes as leading to code injection. A successful attack effectively gives the attacker the ability to execute code on the server, with CVSS rating full (High) impact on confidentiality, integrity, and availability (9.8 Critical). Any organization running MagicINFO 9 Server below version 21.1080.0 is affected, with the greatest risk on digital-signage management servers that are exposed to the internet. Exploitation has not been confirmed: the flaw is not yet in CISA's KEV catalog and no public PoC is known, but its EPSS score of 21.9% (98th percentile) signals an elevated probability of exploitation in the next 30 days.
What to do: Upgrade MagicINFO 9 Server to version 21.1080.0 or later, which resolves this issue. Until patched, remove direct internet exposure (restrict the server to VPN or management networks) and review web server logs for path traversal patterns in requests. Verify the currently deployed version in the MagicINFO admin console before and after updating.
| Samsung Electronics MagicINFO 9 Server | all versions prior to 21.1080.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.
- Vendors
- samsung
- Products
- magicinfo 9 server
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.