CVE-2025-4632: Samsung MagicINFO 9 Server Path Traversal Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2025-05-22. EPSS: 24.1% chance of exploitation in the next 30 days.

Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.

Affected products

  • Samsung MagicINFO 9 Server: before 21.1052.0 (fixed in 21.1052.0)

Published 2025-05-13. Last modified 2026-06-17.