CVE-2025-54450

7.2

Samsung Electronics · MagicINFO 9 Server

A path traversal vulnerability in Samsung MagicINFO 9 Server allows an authenticated administrator to perform code injection.

Executive summary

A path traversal vulnerability in Samsung MagicINFO 9 Server could allow an authenticated attacker to perform unauthorized code injection, posing a significant risk to server integrity.

Vulnerability

This is a path traversal vulnerability (CWE-22) that permits code injection. The CVSS vector (PR:H) indicates that an attacker must possess high privileges to successfully exploit this flaw.

Business impact

Successful exploitation allows an attacker to inject arbitrary code, potentially leading to full system compromise, data theft, or service disruption. With a CVSS score of 7.2, this vulnerability is classified as High severity, representing a substantial risk to organizational security and operational continuity.

Remediation

Immediate Action: Update Samsung MagicINFO 9 Server to version 21.1080.0 or later to remediate the vulnerability.

Proactive Monitoring: Monitor server access logs for unauthorized file path access patterns or unexpected execution of system commands.

Compensating Controls: Ensure that administrative access to the MagicINFO 9 interface is restricted to authorized personnel and protected by robust network access controls.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for code injection and system compromise, administrators should prioritize updating to the patched version immediately. Restricting access to the administrative console and verifying that only trusted users have the necessary privileges will further reduce the attack surface until the update is deployed.

More Samsung Electronics CVEs

Sources