CVE-2025-54441

8.8

Samsung Electronics · MagicINFO 9 Server

Samsung MagicINFO 9 Server contains an unrestricted file upload vulnerability that allows an authenticated attacker to perform remote code injection.

Executive summary

A critical file upload vulnerability in Samsung MagicINFO 9 Server allows authenticated attackers to execute arbitrary code, posing a severe risk to system integrity.

Vulnerability

The application fails to properly validate file types during upload, allowing an authenticated attacker to upload and execute malicious files. This CWE-434 flaw enables arbitrary code injection on the host server.

Business impact

The ability to inject code provides an attacker with complete control over the affected server, potentially leading to unauthorized data access, lateral movement within the network, and full system compromise. With a CVSS score of 8.8, this high-severity vulnerability represents a significant threat to organizational security and operational continuity.

Remediation

Immediate Action: Update Samsung MagicINFO 9 Server to version 21.1080.0 or later as specified by the vendor security advisory.

Proactive Monitoring: Inspect web server access logs for suspicious file upload patterns and monitor for unexpected child processes or unusual network connections originating from the server.

Compensating Controls: Implement strict file type filtering and directory execution restrictions at the Web Application Firewall level to block unauthorized file uploads until the patch can be deployed.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

Given the high CVSS score and the potential for full system compromise via code injection, this vulnerability should be prioritized for immediate remediation. Administrators must confirm their current version and apply the vendor-supplied update to version 21.1080.0 immediately to eliminate this attack vector.

More Samsung Electronics CVEs

Sources