CVE-2024-7399: Samsung MagicINFO 9 Server Path Traversal Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-04-24. EPSS: 91.9% chance of exploitation in the next 30 days.

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.

Affected products

  • Samsung MagicINFO 9 Server: before 21.1050.0 (fixed in 21.1050.0)

Published 2024-08-12. Last modified 2026-10-01.