>> All posts

CVE-2025-4632: Samsung MagicINFO 9 Server path traversal, patch-bypass exploited in the wild

The short version: CVE-2025-4632 is a path-traversal flaw in Samsung MagicINFO 9 Server that lets an unauthenticated attacker write an arbitrary file with system authority — the same class of bug as CVE-2024-7399, and effectively a bypass of that earlier fix. It's a perfect-storm 9.8, it's in CISA's KEV catalog, and it was picked up by botnets shortly after disclosure. If you run MagicINFO 9 Server below 21.1052, patch now — and don't assume the earlier update was enough. Steady hands — but move.

At a glance

FactDetail
Our severity takeHigh — unauthenticated file write as system → RCE, KEV-listed and exploited
CVSS v3.1 (NVD)9.8 — Critical · AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS~23.95% · 97.59th percentile (2026-07-17)
In CISA KEV?Yes — remediate by 2025-06-12
Known exploited?Yes — exploited in the wild, including Mirai-style botnet activity
Vulnerability typeCWE-22 path traversal → arbitrary file write as system authority → remote code execution
Requires authenticated session?No — pre-authentication
AffectedSamsung MagicINFO 9 Server before 21.1052
Fixed in21.1052.0 (and later)

What you need to know

MagicINFO 9 Server manages Samsung commercial displays and is often network-reachable for remote administration. CVE-2025-4632 is a path traversal that lets an unauthenticated attacker write a file to a chosen location with system authority; placing an executable web resource turns the write into code execution on the host.

The important wrinkle is history: this is closely related to CVE-2024-7399, and it functions as a bypass of that earlier remediation. Environments that patched once may still be exposed.

  • It's unauthenticated and network-reachable. A single crafted request performs the write.
  • The write runs as system. File write becomes host compromise.
  • It defeats the prior fix. "We already patched MagicINFO" is not a safe assumption here — you need the 21.1052 build.
  • It's KEV-listed and botnet-targeted. Exploited quickly after disclosure.

How serious we see it

High — the 9.8 is earned: unauthenticated, network-reachable file write as system, actively exploited, and a bypass of an earlier patch.

The bounded, reassuring part is that it's narrow and fixable — it affects MagicINFO 9 Server below 21.1052, the fix is published, and exposure is quick to determine. The catch is precisely the patch-bypass nature: confirm you're on 21.1052 or later, not merely on a previously "patched" build.

Recommendations

  1. Patch now. Upgrade Samsung MagicINFO 9 Server to 21.1052.0 or later — the fix for CVE-2024-7399 is not sufficient.
  2. Hunt. Review the web root and upload paths for files you didn't create, and check logs for anomalous file-handling requests and botnet-style follow-on activity.
  3. If compromised, respond. Rebuild the server, rotate credentials and keys, and investigate for persistence.
  4. Reduce exposure. Keep MagicINFO off the public internet where possible; restrict management to trusted networks.
  5. Confirm your exposure first. Verify whether you run MagicINFO 9 Server and which build.

How BreachRisk sees it

BreachRisk discovers internet-facing MagicINFO panels from little more than your domain, fingerprints the product and version, and flags exposure tied to this KEV-listed, actively exploited flaw — surfaced at the top of your results because it's in KEV. Because we fingerprint the actual running build, a server that was "patched" against the earlier CVE but still sits below 21.1052 still shows up as exposed. We detect and prioritize; we don't exploit.

References

See your cyber risk, proven.