U.S. CISA adds a Samsung MagicINFO 9 Server flaw to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-4632 | Actively Exploited Path Traversal File Write in Samsung MagicINFO 9 Server Samsung MagicINFO 9 Server, the web-based management server used to run Samsung digital signage deployments, contains a path traversal flaw (CWE-22) that allows an attacker to write arbitrary files with system authority. An attacker triggers the flaw by sending crafted path input containing directory traversal sequences, causing files to be written outside the intended location; because the write occurs with system-level privileges, it can enable remote code execution, persistence, or full compromise of the host server. Any organization running MagicINFO 9 Server — typically operators of Samsung commercial signage networks — is potentially affected. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on May 22, 2025, confirming exploitation in the wild, and EPSS places it in the 98th percentile with a 24.3% probability of exploitation within 30 days; no public proof-of-concept is known. Specific affected version ranges are not stated in the available data. Do: Immediately update MagicINFO 9 Server to the latest release per Samsung's security advisory, or if patching is not yet possible, restrict network and internet access to the server or discontinue use as required by the CISA KEV action (federal agencies must follow BOD 22-01 timelines). Hunt for signs of compromise — unexpected or newly written files, modified web content, or added web shells/accounts — since the flaw permits system-privileged file writes. Verify internet-exposed instances are remediated first. | 9.8 | 24% | KEV |
| moderate≈1,000–10,000 MagicINFO 9 Server deployments worldwide |
Full article228 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Samsung MagicINFO 9 Server vulnerability to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Samsung MagicINFO 9 Server vulnerability, tracked as CVE-2025-4632 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog.
The vulnerability is an improper limitation of a pathname to a restricted directory vulnerability that impacts Samsung MagicINFO 9 Server version before 21.1052. An attacker can exploit the vulnerability to write arbitrary file as system authority.
“Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server allows attackers to write arbitrary file as system authority.” reads the advisory.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the vulnerabilities by June 12, 2025.
This week U.S. Cybersecurity and Infrastructure Security Agency (CISA) also added Ivanti EPMM, MDaemon Email Server, Srimax Output Messenger, Zimbra Collaboration, and ZKTeco BioTime flaws to its Known Exploited Vulnerabilities catalog.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/178194/hacking/cisa-adds-a-samsung-magicinfo-9-server-flaw-known-exploited-vulnerabilities-catalog.html