CVE-2025-54450
7.2Samsung Electronics · MagicINFO 9 Server
A path traversal vulnerability in Samsung MagicINFO 9 Server allows an authenticated administrator to perform code injection.
Executive summary
A path traversal vulnerability in Samsung MagicINFO 9 Server could allow an authenticated attacker to perform unauthorized code injection, posing a significant risk to server integrity.
Vulnerability
This is a path traversal vulnerability (CWE-22) that permits code injection. The CVSS vector (PR:H) indicates that an attacker must possess high privileges to successfully exploit this flaw.
Business impact
Successful exploitation allows an attacker to inject arbitrary code, potentially leading to full system compromise, data theft, or service disruption. With a CVSS score of 7.2, this vulnerability is classified as High severity, representing a substantial risk to organizational security and operational continuity.
Remediation
Immediate Action: Update Samsung MagicINFO 9 Server to version 21.1080.0 or later to remediate the vulnerability.
Proactive Monitoring: Monitor server access logs for unauthorized file path access patterns or unexpected execution of system commands.
Compensating Controls: Ensure that administrative access to the MagicINFO 9 interface is restricted to authorized personnel and protected by robust network access controls.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for code injection and system compromise, administrators should prioritize updating to the patched version immediately. Restricting access to the administrative console and verifying that only trusted users have the necessary privileges will further reduce the attack surface until the update is deployed.