FAIL › dossier
MagicINFO 9 Server
PRODUCT· dossier confidence 50%
Samsung's MagicINFO 9 Server is a digital signage product with a documented history of critical security failures. It has suffered multiple high-severity RCE vulnerabilities due to unpatched path traversal flaws, allowing attackers to write arbitrary files as system authority.
PROFILE
CategoryDigital Signage / Information DisplayWhat they doMagicINFO 9 Server is a digital signage and information display server product manufactured by Samsung.
SECURITY POSTURE
The MagicINFO 9 Server has a poor security track record, with multiple high-severity remote code execution (RCE) vulnerabilities stemming from unpatched path traversal flaws that allowed arbitrary file writing as system authority.
Notable failures
- CVE-2025-4632: Unpatched path traversal RCE allowing arbitrary file write as system authority
- CVE-2024-7399: Unpatched path traversal RCE allowing arbitrary file write as system authority
Patterns: Repeated unpatched path traversal vulnerabilities leading to high-severity RCEs; Failure to patch critical flaws before exploitation
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2025-05-22 | CVE-2025-4632 | high | Samsung's MagicINFO 9 Server had an unpatched, exploited path traversal vulnerability allowing arbitrary file writing as system authority. |
| 2026-04-24 | CVE-2024-7399 | high | Samsung MagicINFO 9 Server path traversal vulnerability allows attackers to write arbitrary files as system authority. |
Open questions: Are there additional unpatched vulnerabilities in the MagicINFO 9 Server beyond the two CVEs provided? · What is the current patch status for CVE-2025-4632 and CVE-2024-7399?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-12 04:01:07.355658+00:00