Skip to content
COOEY

FAIL › dossier

MagicINFO 9 Server

PRODUCT

· dossier confidence 50%

Samsung's MagicINFO 9 Server is a digital signage product with a documented history of critical security failures. It has suffered multiple high-severity RCE vulnerabilities due to unpatched path traversal flaws, allowing attackers to write arbitrary files as system authority.

PROFILE
CategoryDigital Signage / Information DisplayWhat they doMagicINFO 9 Server is a digital signage and information display server product manufactured by Samsung.
SECURITY POSTURE

The MagicINFO 9 Server has a poor security track record, with multiple high-severity remote code execution (RCE) vulnerabilities stemming from unpatched path traversal flaws that allowed arbitrary file writing as system authority.

Notable failures
  • CVE-2025-4632: Unpatched path traversal RCE allowing arbitrary file write as system authority
  • CVE-2024-7399: Unpatched path traversal RCE allowing arbitrary file write as system authority
Patterns: Repeated unpatched path traversal vulnerabilities leading to high-severity RCEs; Failure to patch critical flaws before exploitation
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2025-05-22 CVE-2025-4632 high Samsung's MagicINFO 9 Server had an unpatched, exploited path traversal vulnerability allowing arbitrary file writing as system authority.
2026-04-24 CVE-2024-7399 high Samsung MagicINFO 9 Server path traversal vulnerability allows attackers to write arbitrary files as system authority.
Open questions: Are there additional unpatched vulnerabilities in the MagicINFO 9 Server beyond the two CVEs provided? · What is the current patch status for CVE-2025-4632 and CVE-2024-7399?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-12 04:01:07.355658+00:00