Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Samsung MagicINFO 9 Server Path Traversal Vulnerability Allowing Arbitrary File Write

Vulnerability

A vulnerability in Samsung MagicINFO 9 Server, in versions prior to 21.1052, allows attackers to write arbitrary files with system authority. This issue arises from improper limitations on pathnames, enabling unauthorized file writing.

Impact

Exploitation of this vulnerability could lead to unauthorized file writes with system privileges, potentially allowing for further exploitation or manipulation of the system.

Remediation

Users can update to the latest version of Samsung MagicINFO 9 Server to address this vulnerability. Instructions for checking and applying software updates are available on the Samsung website.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
6.5
remediation
7.7
relevance
0.0
threat
8.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.