CVE-2025-4632
Description
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.
Summary dbcve.org
This is a path traversal (directory traversal) vulnerability in Samsung MagicINFO 9 Server versions prior to 21.1052. The improper limitation of pathname allows remote attackers to write arbitrary files to the filesystem with system-level (highest) privileges, potentially enabling complete system compromise including remote code execution.
Mitigation
Upgrade Samsung MagicINFO 9 Server to version 21.1052 or later. If immediate patching is not possible, implement strict input validation on all file path parameters and restrict file write permissions to minimize exposure.