EXPOSURES › CVE-2025-4632
CVE-2025-4632
HIGH ⌖ ON CISA KEV · EXPLOITEDSamsung's MagicINFO 9 Server had an unpatched, exploited path traversal vulnerability allowing arbitrary file writing as system authority.
Samsung's MagicINFO 9 Server suffered a high-severity, unpatched path traversal vulnerability that was exploited in the wild, enabling attackers to write files with system authority, posing a significant security risk to DIB systems.
Shame score — CISA highlighted an actively exploited vulnerability in a widely used Samsung product, indicating negligence and a failure to address a known security issue promptly.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Samsung MagicINFO 9 Server contains a path traversal vulnerability that allows an attacker to write arbitrary file as system authority.