CVE-2025-54445

8.2

Samsung Electronics · MagicINFO 9 Server

Samsung MagicINFO 9 Server contains an XML External Entity vulnerability that permits unauthenticated Server Side Request Forgery.

Executive summary

A critical XML External Entity vulnerability in Samsung MagicINFO 9 Server exposes systems to unauthorized Server Side Request Forgery attacks.

Vulnerability

The application fails to properly restrict XML External Entity references, allowing an unauthenticated remote attacker to perform Server Side Request Forgery by injecting malicious XML input.

Business impact

The CVSS score of 8.2 classifies this as a high-severity vulnerability. Successful exploitation allows an attacker to force the server to make unauthorized requests to internal resources, which may lead to the exposure of sensitive internal data or unauthorized interaction with backend services that are not intended to be publicly accessible.

Remediation

Immediate Action: Upgrade to version 21.1080.0 or later as provided by the official Samsung security updates.

Proactive Monitoring: Review server access logs for unusual XML traffic patterns or unexpected outbound requests originating from the MagicINFO server.

Compensating Controls: Implement strict egress filtering on the server to prevent unauthorized outbound connections to internal or sensitive external network segments.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the ability for unauthenticated actors to potentially bypass network perimeters via Server Side Request Forgery, immediate patching is required. Organizations should prioritize updating all instances of MagicINFO 9 Server to the remediated version to ensure the integrity of the internal network.

More Samsung Electronics CVEs

Sources