CVE-2025-54453
8.8Samsung Electronics · MagicINFO 9 Server
Samsung MagicINFO 9 Server contains a path traversal vulnerability that allows attackers to perform code injection.
Executive summary
A critical path traversal vulnerability in Samsung MagicINFO 9 Server allows authenticated attackers to achieve code injection, posing a significant risk to server integrity.
Vulnerability
This is a path traversal vulnerability (CWE-22) that enables code injection. The vulnerability requires the attacker to have low-level privileges (authenticated) to successfully trigger the flaw.
Business impact
The ability to perform code injection on a server typically leads to a full system compromise. Given the CVSS score of 8.8, this vulnerability is classified as High severity, as it allows attackers to bypass directory restrictions to execute arbitrary code. This could result in unauthorized data access, total loss of system integrity, and potential lateral movement within the network.
Remediation
Immediate Action: Administrators must update the MagicINFO 9 Server to version 21.1080.0 or higher to remediate this vulnerability.
Proactive Monitoring: Review web server access and error logs for suspicious path traversal patterns, such as multiple dot-dot-slash sequences in requests.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block directory traversal attempts directed at the application server.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Due to the potential for full code execution, this vulnerability represents a high risk to the availability and security of the affected infrastructure. Organizations should prioritize updating their Samsung MagicINFO 9 Server deployments to version 21.1080.0 immediately. If an immediate update is not feasible, restrict access to the server to trusted internal segments and utilize WAF protections to mitigate the attack vector.