CVE-2025-54447

8.1

Samsung Electronics · MagicINFO 9 Server

Samsung MagicINFO 9 Server contains an unrestricted file upload vulnerability that allows an unauthenticated attacker to perform code injection.

Executive summary

A critical file upload vulnerability in Samsung MagicINFO 9 Server allows unauthenticated remote attackers to execute arbitrary code, posing a severe risk to system integrity.

Vulnerability

This flaw is an unrestricted file upload vulnerability (CWE-434) that permits an unauthenticated attacker to upload malicious files to the server. Successful exploitation allows the attacker to achieve code injection, leading to full system compromise.

Business impact

The ability for an unauthenticated user to inject and execute arbitrary code on a server provides total control over the application environment. With a CVSS score of 8.1, this high-severity vulnerability could result in unauthorized data access, complete system takeover, and significant disruption to organizational operations.

Remediation

Immediate Action: Update Samsung MagicINFO 9 Server to version 21.1080.0 or later immediately to resolve the file upload restriction flaw.

Proactive Monitoring: Review web server and application logs for suspicious file upload activity, specifically looking for attempts to upload non-standard file extensions or files to unexpected directories.

Compensating Controls: Deploy a Web Application Firewall (WAF) with strict file upload inspection rules to block malicious file types before they reach the server.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high impact of remote code execution, organizations utilizing Samsung MagicINFO 9 Server should prioritize patching as a critical security task. Ensure that the server environment is isolated from public networks where possible and apply the vendor-provided update to eliminate the code injection path entirely.

More Samsung Electronics CVEs

Sources