CVE-2025-4632: Samsung MagicINFO 9 Server Path Traversal Vulnerability
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.
Other sources
Samsung MagicINFO 9 Server contains a path traversal vulnerability that allows an attacker to write arbitrary file as system authority.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Samsung MagicINFO 9 Serverto a version that resolves this vulnerability.Fixed in 21.1052 - Compensating control
If you cannot apply the update to 21.1052, apply vendor-provided mitigations, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the Samsung MagicINFO Server if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4632?
CVE-2025-4632 has been classified as a medium severity vulnerability.
How do I fix CVE-2025-4632?
To mitigate CVE-2025-4632, upgrade your Samsung MagicINFO 9 Server to version 21.1052 or higher.
What type of vulnerability is CVE-2025-4632?
CVE-2025-4632 is an improper limitation of a pathname to a restricted directory vulnerability.
What can attackers do with CVE-2025-4632?
Attackers can exploit CVE-2025-4632 to write arbitrary files with system authority.
Which version of Samsung MagicINFO 9 Server is affected by CVE-2025-4632?
Samsung MagicINFO 9 Server version before 21.1052 is affected by CVE-2025-4632.