CRITICAL

CVE-2025-4632

Samsung Magicinfo 9 Server 2025-05-13 CVSS v3.1
CVSS
9.8
KEV

Description

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.

Summary dbcve.org

This is a path traversal (directory traversal) vulnerability in Samsung MagicINFO 9 Server versions prior to 21.1052. The improper limitation of pathname allows remote attackers to write arbitrary files to the filesystem with system-level (highest) privileges, potentially enabling complete system compromise including remote code execution.

Mitigation

Upgrade Samsung MagicINFO 9 Server to version 21.1052 or later. If immediate patching is not possible, implement strict input validation on all file path parameters and restrict file write permissions to minimize exposure.

Patch Commit

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

24.3%
Probability of exploitation in next 30 days
97.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE