Samsung Electronics Magicinfo 9 Server vulnerabilities

24 known vulnerabilities affecting samsung_electronics/magicinfo_9_server.

Total CVEs
24
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL19HIGH5

Vulnerabilities

Page 2 of 2
CVE-2025-54441HIGHCVSS 8.8v21.1080.02025-07-23
CVE-2025-54441 [HIGH] CWE-434 CVE-2025-54441: Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Ser Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.
cvelistv5nvd
CVE-2025-54439HIGHCVSS 8.8v21.1080.02025-07-23
CVE-2025-54439 [HIGH] CWE-434 CVE-2025-54439: Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Ser Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.
cvelistv5nvd
CVE-2025-4632CRITICALCVSS 9.8KEVPoCfixed in 21.10522025-05-13
CVE-2025-4632 [CRITICAL] CWE-22 CVE-2025-4632: Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Ser Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.
cvelistv5nvd
CVE-2024-7399HIGHCVSS 7.5PoCfixed in 21.10502024-08-12
CVE-2024-7399 [HIGH] CWE-22 CVE-2024-7399: Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Ser Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.
cvelistv5nvd